WordPress News

WordPress News: Two Critical Vulnerabilities This Week (Week of 4 August 2026)

WHWynand HoltzhausenAug 04, 20264 min read
WordPress News: Two Critical Vulnerabilities This Week (Week of 4 August 2026)

This week's WordPress news is dominated by two serious vulnerabilities: one a deliberate backdoor smuggled into a popular plugin, the other a critical login flaw in a WooCommerce extension. Both were caught and patched fast, but they're a reminder that plugin security is only as good as its weakest link. WooCommerce also had a quieter week, delaying a release rather than shipping a bug, and WP Engine made a move worth knowing about if your store is growing fast.

Check if you're running this video plugin, and remove it

On July 28, 2026, Wordfence's automated threat detection system, Wordfence PRISM, caught a deliberate backdoor planted inside Advanced Responsive Video Embedder, a plugin used on roughly 20,000 sites. Whoever slipped the code in built a hidden master password directly into the plugin: anyone who knew it could send a single web request and be logged in as an existing administrator, no password guessing, no account required. The plugin would wave through anyone holding the right token, no questions asked, the digital equivalent of a stormtrooper letting you stroll past because you had the right paperwork. Wordfence flagged it within two hours, and WordPress.org pulled the release before it reached most dashboards.

What this means for you: if you use Advanced Responsive Video Embedder, remove it today rather than waiting for an update. WordPress.org closed the plugin for downloads quickly, so most sites never received the bad version. Still, if you're not certain which version you're running, treat the site as potentially exposed: rotate your WordPress secret keys, force a password reset for admin accounts, and check for unfamiliar admin users. Our complete recovery guide walks through exactly how to do that.

Update WooCommerce Social Login right now

Wordfence and Search Engine Journal both flagged a critical flaw in the WooCommerce Social Login plugin, disclosed August 1, 2026. The plugin's "Sign in with Apple" feature didn't properly verify the identity token Apple sends back, so anyone could forge one containing an existing customer's or administrator's email address and be logged straight into that account. It's rated 9.8 out of 10 for severity, about as bad as these ratings get, because no password or prior access is needed to exploit it.

What this means for you: if your store uses WooCommerce Social Login, update to version 2.8.8 immediately; it's already patched. This is worth checking manually rather than waiting for your next scheduled update, since it lets an attacker log in as your store admin. It's also a good prompt to review your security basics more broadly, since convenience features like social login quietly expand what an attacker can target.

WooCommerce 11.0 is a week late, and that's fine

WooCommerce pushed back the release of version 11.0 from July 28 to August 4, 2026, after testing turned up a fatal error triggered by a new performance feature under specific conditions. The team caught it in a release candidate, not in the wild, and is running another round of testing before shipping.

What this means for you: nothing, you are fine. This is exactly how a release process should work: catch the bug before it reaches your store, not after. When 11.0 does land, treat it like any major update and test it on a staging copy of your site first, especially if you rely on custom checkout or performance plugins.

When WooCommerce stops being enough

WP Engine and BigCommerce announced Commerce Connect, a partnership letting fast-growing WordPress stores plug into BigCommerce's commerce engine while keeping their existing WordPress front end, design, and SEO intact. It's aimed at mid-market brands that have outgrown a standard WooCommerce setup: bigger catalogues, more traffic, more complex operations.

For most stores, this changes nothing. WooCommerce remains a solid, well-supported choice for the vast majority of businesses. But it's an honest signal worth naming: some businesses do eventually outgrow what WordPress and WooCommerce can comfortably handle, and that's not a failure, it's a milestone. When that happens, the options range from platform add-ons like this one to fully custom-built software. If you're feeling that friction, an honest conversation now beats another year of forcing a plugin to do a job it was never built for.

This was a security-heavy week, and if you'd rather not be the one checking plugin changelogs and CVE databases every Monday morning, that's exactly what a maintenance plan is for. Update WooCommerce Social Login now, remove Advanced Responsive Video Embedder if you're running it, and let WooCommerce 11.0 land properly before you touch it.

May the Code Be With You.

Share transmission
inX
WH

Wynand Holtzhausen

Senior engineer at WordPress Pro. Rescues struggling sites, rebuilds them stronger, and writes about how it is done.

Related transmissions