WP Fastest Cache Patches Authenticated SQL Injection and Stored XSS Via CSRF Vulnerabilities

The Jetpack Scan team has published a summary of two issues recently discovered in the WP Fastest Cache plugin – an Authenticated SQL Injection vulnerability and a Stored XSS Via CSRF vulnerability. “If exploited, the SQL Injection bug could grant attackers access to privileged information from the affected site’s database (e.g., usernames and hashed passwords),” Automattic security research engineer Marc Montpas …

WPCloudDeploy Brings Site and Server Management to the WordPress Admin

WPCloudDeploy recently launched version 4.10.5 of its rapidly-maturing WordPress plugin of the same name. The project is a WordPress-native replacement for SaaS services like Cloudways, Ploi, SpinupWP, and others. Customers still need to hook up to a cloud server provider, such as Digital Ocean, Linode, AWS, or elsewhere. However, the project seeks to cut out the middleman for developers and …

GiveWP Launches Peer-to-Peer Fundraising Add-On

The GiveWP team announced an extension of its flagship donation plugin for allowing peer-to-peer (P2P) fundraising in late September. The solution should make the project even more appealing than before for those looking to break from third-party donation services and go the self-hosted route. The first version rolls out individual and team fundraising pages, leaderboards, campaign sponsor support, and more. …

Gutenberg 11.6 Improves the Global Styles UI, Adds Child Theme Support

Gutenberg 11.6 landed yesterday. Contributors added dozens of enhancements and bug fixes. Admittedly, there was not a whole lot that excited me as a user about this release. Typography options for the Post Title block. Nice. Cropping for the Site Logo. A necessary addition. Toolbar button for converting old Gallery blocks to the new — still experimental — format. Sweet. …

Keanan Koppenhaver Acquires WP Pusher and Branch

WordPress developer Keanan Koppenhaver announced today that he has acquired WP Pusher and Branch from Peter Suhm. WP Pusher, a product we have covered for the past six years, allows users to deploy plugins and themes from popular code hosting services like GitHub, GitLab, and Bitbucket. In 2018, Suhm expanded his offerings to include Branch, a Docker-based continuous integration service …

Gutenberg 11.5 Adds Widget Grouping, Iterates on the Block Gap Feature, and Updates Nav Menus

Gutenberg 11.5 landed earlier today. It is a hefty release that includes extensive changes to the Navigation block, a new way for grouping widgets, and more block gap feature integration. I have had mixed reactions to the features that made it into the latest release. At some points, I thought to myself, finally, this made it in. At other moments, …