Essential Addons for Elementor Patches Critical Privilege Escalation Vulnerability

Essential Addons for Elementor, a plugin with more than a million active installs, has patched an unauthenticated privilege escalation vulnerability in version 5.7.2. The vulnerability was discovered on May 8, 2023, and reported by Patchstack researcher Rafie Muhammad. It was given a 9.8 (Critical severity) CVSS 3.1 score and is not yet known to have been exploited. Muhammad outlined the vulnerability …

WordPress Community Team Evolves WordCamp Format to Promote Adoption, Training, and Networking for Professionals

WordPress’ Community Team hailed a new era of WordCamps in its recent announcement outlining a significant shift in the purpose for the events. In the past, WordCamps have had a mostly predictable format of presenting inspirational talks on exciting things people are doing with WordPress, business topics, and the latest trends, with short networking opportunities and a contributor day appended …

WordPress Contributors Discuss How Core Can Better Enable AI Innovation

As AI-powered technology is rapidly evolving to exponentially extend human capabilities, WordPress contributors do not want the platform to get left behind. AI-powered website creation could even become a threat to its existence, more than a competing CMS, if WordPress doesn’t ensure the platform is easily pluggable for AI-powered extensions. A new discussion on the Core developer’s blog asks what …

Advanced Custom Fields Plugin Patches Reflected XSS Vulnerability

Advanced Custom Fields (ACF) has patched a reflected XSS vulnerability that affects versions 6.1.5 and below of ACF and ACF Pro, potentially impacting more than 2+ million users. It was discovered by Patchstack researcher Rafie Muhammad in May 2, 2023, and patched by ACF developers in version 6.1.6 on May 5, 2023. Patchstack published a security bulletin and Muhammad described the …

Gutenberg 15.7 Adds Site Logo Upload to Inspector Controls

Gutenberg 15.7 was released this week, adding Site Logo upload and replacement from the inspector controls sidebar. This feature is still available in the block toolbar but it feels like a natural addition to the inspector, as it was previously available in a similar fashion in the Customizer. Here users can easily adjust the logo width and set whether the …

Caseproof Acquires WishList Member

Caseproof, makers of MemberPress, has acquired WishList Products, the parent company of WishList Member and CourseCure. The Wishlist team, with the exception of co-founder Tracy Childers, will continue supporting and developing the products under the leadership of Caseproof founder Blair Williams. WishList Member is one of the longest running WordPress membership plugins with a 14-year history. The plugin has been …