Tag
Automattic has restructured its board after a failed attempt to oust CEO Matt Mullenweg, adding new members including authors and co-founders of the defunct app IRL, amid internal governance disputes.
The author has developed a WordPress plugin that acts as an MCP bridge to connect WordPress sites with AI agents, and is seeking developers to test and provide feedback on its functionality.
This article reports on a critical security vulnerability in WordPress that allows unauthenticated path traversal leading to conditional remote code execution, with setup instructions from the development repository.
Matt Mullenweg has returned as CEO of Automattic after the board's attempted ouster, highlighting ongoing internal conflict at the WordPress parent company.
Matt Mullenweg has been reinstated as CEO of Automattic after being placed on paid leave, following a dispute with the board of directors.
Matt Mullenweg, founder of Automattic, claims he is back in control as CEO after the board voted to oust him, causing confusion and ongoing controversy within the company.
Automattic's board has forced founder and CEO Matt Mullenweg into a paid leave of absence against his will, appointing CFO Mark Davies as interim CEO amid ongoing legal disputes with WP Engine.
Automattic CEO Matt Mullenweg has been placed on paid leave following internal board decisions, with CFO Mark Davies taking over as interim CEO amid disputes and past controversies.
LLMagnet is a product that enhances WordPress site visibility to AI agents by tracking AI crawler visits, generating AI-friendly data like llms.txt, and improving AI accessibility.
Matt Mullenweg and Robert Jacobi will hold a fireside chat at WordCamp US 2026 to discuss the current state of open source, WordPress's evolution with AI, and community engagement, including a 30-minute audience Q&A.
Security researcher uses GPT5.6 Sol Ultra to discover a WordPress pre-auth RCE vulnerability, potentially worth $500k to exploit brokers, demonstrating AI's capability in cybersecurity research.
wp2shell bypasses two MySQL limitations for WordPress exploitation: it requires no multi_query (uses UNION SELECT) and no FILE permission (uses WordPress's own code to create users).
A blog post describes a WordPress bug that only affected left-handed users due to a touchstart listener, and details the fix which removed the unnecessary code.
IvyForms is a WordPress form builder designed for real-world workflows, aiming to simplify form creation and management.
Hackers are actively exploiting a critical remote code execution vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin, affecting versions up to 1.9.12. The flaw allows unescaped form values to be passed to eval(), enabling full site compromise. Wordfence urges immediate plugin updates.
WordPress 7.0 is a major release featuring a redesigned navigation overlay, AI integration through a centralized Connectors hub, visual revisions, pattern handling as single blocks, performance improvements, enhanced accessibility, and a refreshed admin experience.
WordPress 7.0, codenamed Armstrong, has been released, marking a major update to the popular content management system.