WordPress News: Security Patches and a Major Release (Week of 18 August 2026)

This week is a good reminder that "boring" and "important" are not opposites in WordPress land. Core shipped a quiet security fix, a popular plugin patched a critical takeover bug, and the year's second major release lands on Wednesday. None of it requires panic, but all of it deserves five minutes of your attention.
Update your WordPress core now, no excuses
WordPress 7.0.4 fixed a vulnerability in how core hands uploaded images to ImageMagick for processing. The flaw let a file disguised as a harmless image (say, holiday.png) actually contain PostScript code, which ImageMagick would happily pass to Ghostscript and execute on your server. Patchstack's writeup explains that this affects every WordPress version from 4.7 through 7.0, and it requires at least an Author-level account to exploit, so it is not an anonymous drive-by attack.
What this means for you: if you have automatic background updates switched on, you are likely already covered, but check your version number to be sure. If your site allows open registration, has a membership area, or hands Author access to contributors, treat this one as a priority rather than a "get to it eventually" item. Tightening who gets Author access and above is exactly the kind of thing covered in our guide to WordPress security best practices.
Check if you run User Profile Builder, and patch it today
Wordfence disclosed a critical (9.8 out of 10) authentication bypass in the popular User Profile Builder plugin, used on more than 40,000 sites. Because of a type confusion bug, an unauthenticated attacker submitting a 61 to 70 character username during registration could end up logged in as the site's administrator, user ID 1. Full details are in Wordfence's advisory, which notes the bug is fixed in version 3.16.5.
What this means for you: if you use this plugin, confirm you are on 3.16.5 or later, and do it today rather than at the next maintenance window. The plugin's developer patched it quickly, which is the outcome you want, but a fast patch only helps if you actually install it.
WordPress 7.1 lands this week, here's what changes
WordPress 7.1 ships on Wednesday, timed to the closing day of WordCamp US, as confirmed in the official release schedule and covered in detail by SmartWP. The headline feature lets you set responsive font sizes and hover styles without touching a stylesheet, and the release adds new Playlist and Tabs blocks, a reorganised command palette, and a jQuery UI update. As Yoda might put it: there is no "try it on production." There is only a staging site, or there is a critical error waiting for you on Wednesday morning.
What this means for you: major releases occasionally trip up older plugins and themes, particularly anything that pokes directly at the editor or relies on the jQuery UI version WordPress bundles. Test the update on a copy of your site first if you can. Our guides to staging sites and what to do if something breaks are there if you need them, but for most well maintained sites this will be a routine update.
The Automattic vs WP Engine lawsuit drags on, but it is not your problem
The long running legal dispute between WP Engine and Automattic (Matt Mullenweg's company) escalated again this month. WP Engine filed a motion asking the court to sanction Mullenweg and Automattic over alleged evidence destruction involving disappearing messages. Automattic fired back with a post titled "Wrong Again," arguing the missing messages were personal and unrelated to the case, as reported by Search Engine Journal.
What this means for you: nothing, honestly, unless your hosting is specifically tied to WP Engine and you are watching the business relationship for stability reasons. WordPress the open source software keeps shipping releases and security patches regardless of how this courtroom drama plays out. It is worth knowing about because it keeps showing up in headlines, not because it changes anything you need to do to your site.
Wrap-up
Two core security fixes, a critical plugin patch, and a major release all landing in the same fortnight is a normal week for WordPress, not a crisis. If keeping track of all of this sounds like a job you would rather hand off, that is precisely what a maintenance plan is for: someone else watches for these updates and applies them before they become your problem.
May the Code Be With You.
Wynand Holtzhausen
Senior engineer at WordPress Pro. Rescues struggling sites, rebuilds them stronger, and writes about how it is done.


