WordPress News: Critical Plugin Bugs, Major Core Release (Week of 25 August 2026)

This week gave us a reminder that it does not matter how well-built your site is if a single plugin has a hole in it. Two unrelated, critical bugs, one in a widely used custom fields plugin and one in the Pro forms of the most popular page builder, both lead to the same nightmare: a stranger logging in as your administrator. On a calmer note, WordPress itself also shipped a solid, no-drama core release.
Update Pods immediately if your site uses it
Wordfence disclosed a critical privilege escalation vulnerability in Pods, the Custom Content Types and Fields plugin, used on more than 100,000 sites. The bug (CVSS 9.8) lets a completely unauthenticated attacker overwrite the password of any user, including the site owner, and take full control. The Pods team patched it fast, on 14 August, and WordPress.org is pushing a forced update to affected sites, but "should be patched automatically" is not the same as "is patched."
What this means for you: if you run Pods, check right now that you are on version 3.3.9.1 or the equivalent patched release for your major version (2.8.23.4, 2.9.19.4, 3.0.10.4, 3.1.4.2, or 3.2.8.3). Do not assume the forced update reached you; log in and check the plugin version yourself. If you suspect your site was already compromised before the patch landed, our guide to recovering a hacked WordPress site walks through what to check first. Otherwise, our WordPress security best practices guide covers the basics that would have limited the damage here regardless.
Elementor Pro's forms had a hole big enough to hand over your site too
Patchstack published details on a critical unauthenticated file upload vulnerability (CVE-2026-32475, CVSS 9.0) in Elementor Pro's Forms widget, affecting version 4.2.1 and earlier. Any page with a Forms widget that includes a File Upload field, think job applications, support tickets, or "attach your ID" forms, could be tricked into accepting a disguised PHP file instead of a document, giving an attacker code execution on your server with no login required. Elementor patched it in version 4.2.2, released 19 August.
What this means for you: update Elementor Pro to 4.2.2 or later without delay if you use its Forms widget with file uploads. It is also worth having someone check the wp-content/uploads/elementor/forms/ folder for anything that isn't a document or image your forms are supposed to accept, particularly files ending in .php, in case an attacker got there before the patch did. If your business handles a lot of sensitive uploads, ID documents, contracts, applications, through a generic form builder widget, this is a fair moment to ask whether a page builder's one-size-fits-all form is really the right tool, or whether a custom-built form handler would serve you and your customers better.
WordPress 7.1 "Mary Lou" landed, and it's mostly good news
WordPress 7.1 is officially out, released on 19 August. Highlights include a consistent admin bar across every editor, built-in responsive block styling (no more custom CSS for "hide this on mobile"), a much better image cropping and editing tool, and richer collaboration Notes with mentions. Two new blocks, Playlist and Tabs, round things out. It is a big release, but not a security release, and there is nothing here that demands you drop everything today.
What this means for you: you do not need to rush this update, but you should still test it before it hits your live site, especially if you run custom themes, older plugins, or a page builder. Big core releases occasionally expose compatibility issues that only show up once real content meets real plugins. A staging site is the right place to find that out, not your homepage on a Monday morning.
The week in one sentence
Two critical, unauthenticated vulnerabilities in widely used plugins, both capable of full site takeover, disclosed and patched within days of each other, while WordPress core quietly kept shipping useful, low-risk improvements. If keeping track of every plugin's patch status feels like a full-time job some weeks, that is because it genuinely can be; a maintenance plan is built to handle exactly this kind of update and monitoring automatically, so you are not the one checking version numbers at 11pm.
Neither of this week's bugs required anything exotic to exploit, just an unpatched plugin sitting on a public site. Update Pods, update Elementor Pro if you use its forms, and take your time with 7.1. That is the whole roundup.
May the Code Be With You.
Wynand Holtzhausen
Senior engineer at WordPress Pro. Rescues struggling sites, rebuilds them stronger, and writes about how it is done.


