Gutenberg 13.5 Adds Featured Image Placeholder Support for Cover Block, Cleaner Pasting to Other Apps

Gutenberg 13.5 is now available. The release comes two weeks after the plugin introduced support for button elements in theme.json, axial spacing in the Gallery block, and a redesigned Publish popover in 13.4. The latest release includes 12 enhancements and 15 bug fixes with the most notable changes landing in the Cover block. Prior to 13.5, the Cover block’s support for using …

WordPress Appears In NYT Crossword

At the risk of spoiling the answer to a clue included in the image below, WordPress made an appearance in the New York Times crossword puzzle today. Likely nobody reading this post would struggle to answer the clue “popular blogging platform” with nine letters. New York-based digital consultant and media co-founder Matt DeSiena tweeted a screenshot with the caption, “You …

Elementor Lays Off 15% of Workforce, Citing Rising Inflation and Impending Recession

With inflation rising and the unemployment rate falling, economic forecasters are predicting an impending recession in 2023. A few major WordPress companies are tightening their belts ahead of what many believe will be an unavoidable economic downturn. Elementor announced that it is laying off 60 employees, 15% of its workforce, in a tightly controlled release of information to Globes, an …

The Ultimate Guide To Securing Your WordPress Login With Biometric Authentication – For Free!

Defender had already implemented Two-Factor Authentication (2FA) in WordPress for hardened security… now we’ve added Biometrics, too! It has become increasingly apparent that relying strictly on usernames and passwords for logins no longer offers the highest levels of security. WPMU DEV’s solution to addressing this is through the use of the WebAuthn standard, which bypasses vulnerabilities by providing a protocol …

WordPress.org Forces Security Update for Critical Ninja Forms Vulnerability

Late last week, Ninja Forms users received a forced security update from WordPress.org for a critical PHP Object Injection vulnerability. This particular vulnerability can be exploited remotely without any authentication. It was publicly disclosed last week and patched in the latest version, 3.6.11. Patches were also backported to versions 3.0.34.2, 3.1.10, 3.2.28, 3.3.21.4, 3.4.34.2, and 3.5.8.4. Wordfence noticed a back-ported …