WordPress News: Critical Patches and Quick Fixes (Week of 3 July 2026)

This week was less about big WordPress announcements and more about the unglamorous work that actually keeps a site running: patches, quiet bug fixes, and a debate over what belongs in WordPress core. Nothing here is a crisis, but two items are worth acting on today rather than filing away for later.
Patch Dokan Pro and check your invoice plugin today
Wordfence's weekly vulnerability report covering 22 to 28 June logged 199 new vulnerabilities across 169 plugins and 9 themes, 6 of them rated critical and 49 rated high severity. The one that matters most for store owners is a critical, since patched, vulnerability in Dokan Pro, the plugin many WooCommerce multivendor marketplaces run on. Two separate critical vulnerabilities were also disclosed in the Invoice Generator plugin, and as of this report, neither has a patch available. Full detail is in the Wordfence weekly report.
What this means for you: if you run Dokan Pro, update to the patched version now, don't wait for your usual update cycle. If you run Invoice Generator, there is no fix yet: the safest move is to deactivate it until the developer ships one, particularly since it handles financial documents. New WordPress vulnerabilities surface every single week, and it's rarely one dramatic exploit, more a steady drip of small leaks that need sealing before attackers find them first (think less lone Death Star exhaust port, more a hull full of tiny hairline cracks). That's exactly why ongoing security best practices matter more than reacting to any one headline. If your site is ever compromised despite your best efforts, our hacked site recovery guide walks through cleanup step by step.
WooCommerce shipped two emergency fixes this week, update again
WooCommerce released version 10.9.0 with performance improvements to checkout and the admin dashboard, plus a new transactional email logging feature. That release then needed two follow-up dot releases in quick succession: 10.9.2 on 2 July fixed a fatal error that could occur during the plugin update process itself, and 10.9.1 and 10.9.3 addressed a fatal error in WooCommerce's email notification system and a compatibility issue with older Stripe payment gateway versions. Details are in the WooCommerce changelog.
What this means for you: if your store runs WooCommerce and you updated to 10.9 in the past week or two, update again to 10.9.3. These aren't security fixes, they're stability fixes, but a fatal error touching checkout or order emails is still lost sales and confused customers. It's also a useful reminder that "update and forget" isn't quite realistic even for a plugin as widely used and well resourced as WooCommerce. If an update ever leaves your site showing a blank page or an error message instead of your homepage, our critical error guide covers exactly what to do next.
WordPress core debates an AI feature nobody asked for
A proposal to merge a new "Knowledge" custom post type into WordPress core, essentially a structured store of a site's brand voice, tone, image preferences, and content rules, has run into firm pushback from developers. Critics argue the underlying GitHub specification reads as built for AI agents rather than human editors, that it adds bloat to core, and that it distracts from bigger priorities like native multilingual support. The full story, including quotes from the community pushback, is at Search Engine Journal.
What this means for you: nothing to do right now. This is a proposal, not a shipped feature, and even if it eventually lands it won't change how your existing site works today. It's worth knowing about because it signals where WordPress core is heading: more built-in AI plumbing, whether the wider community asked for it or not. If your business has already outgrown what off-the-shelf WordPress plugins can comfortably handle, arguments like this one over core bloat are a useful reminder that a custom-built solution can sometimes serve your actual workflow better than waiting for core, or a plugin, to catch up.
Nothing this week demands a fire drill, but the Dokan Pro patch and the Invoice Generator gap are worth handling today, not next month. If tracking patches and vulnerability reports like these isn't how you want to spend your week, a maintenance plan handles updates and monitoring automatically, so stories like this one become our problem instead of yours.
May the Code Be With You.
Wynand Holtzhausen
Senior engineer at WordPress Pro. Rescues struggling sites, rebuilds them stronger, and writes about how it is done.


