WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution

High · The Hacker News ·

WordPress

What happened

WordPress.org will automatically security-review every plugin update before release via its update API, aiming to block risky updates. Site admins and plugin developers are affected.

What to do now

No emergency action. Inventory WordPress plugins, remove unused ones, enable auto-updates for trusted plugins, test updates in staging, and monitor WordPress.org and vendor advisories for blocked or delayed releases.

Original source

The Hacker News

AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news