WordPress Weekly News Digest

WordPress mid-July news digest: WordPress 6.8.2 released, critical plugin vulnerabilities disclosed, security patches, and developer updates from the week.

Welcome to the July mid-month edition of our WordPress Weekly News Digest, where we cover critical updates, plugin vulnerabilities, ecosystem news, and security advisories that matter to developers, site owners, and WordPress professionals. This edition is rich with must-know insights, from the release of WordPress 6.8.2 to alarming security breaches, emerging CVEs, and product launches shaping the future of the ecosystem.


WordPress 6.8.2 Now Available

The WordPress team officially announced the release of WordPress 6.8.2, a maintenance update addressing 20 core issues and 15 block editor bugs. While not a security release, users are encouraged to upgrade for better stability and compatibility. You can read the full changelog here.

For a deeper look at the fixes and community response, read our detailed overview of WordPress 6.8.2.

WooCommerce 10.0 Released

If you run an online store, WooCommerce 10.0 is now out with a performance-boosted engine, refined compatibility for PHP 8.3, and improvements for the WooCommerce block experience. WPExperts.io shared details on its feature-rich rollout.


Gravity Forms Plugin Compromised

The biggest security shocker came from a supply-chain attack involving the widely used Gravity Forms plugin. SecurityWeek and TheCyberSecHub confirmed that attackers compromised the plugin to distribute backdoored versions, impacting thousands of websites. This exploit marks one of the most dangerous plugin supply-chain compromises since 2023.

Additional coverage by Heise Online and Michael Sieg supports concerns of widespread infection. Immediate audits and clean reinstalls are strongly advised.

SureForms Arbitrary File Deletion (CVE-2025-6691)

Wordfence revealed an unauthenticated file deletion vulnerability in the SureForms plugin, which puts over 200,000 WordPress sites at risk. The flaw, CVE-2025-6691, allows attackers to remove critical files remotely.

Simple File List Plugin RCE (CVE-2025-34085)

A high-severity Remote Code Execution (RCE) vulnerability targeting the Simple File List plugin was disclosed by researcher @wtf_brut. The multi-target PoC automates exploit attempts across multiple domains.

JobWP SQL Injection (CVE-2025-2010)

A critical SQL Injection vulnerability in JobWP <= 2.3.9 has been flagged as CVE-2025-2010. Plugin users should patch immediately.

Ads Pro Plugin LFI (CVE-2025-4380)

Also reported by @pdnuclei_bot, the Ads Pro Plugin was found vulnerable to Local File Inclusion, exposing sensitive internal data on affected sites.

HT Contact Form File Upload Vulnerabilities

Multiple vulnerabilities were reported in the HT Contact Form plugin, including CVE-2025-7340 allowing arbitrary file uploads. Netlas.io confirmed additional CVEs with ratings reaching 9.8.

Additional CVEs in Themes

Two popular WordPress themes were found with improper input handling:

These issues may allow malicious code execution or unauthorized data access.

Vulnerable Malware Scanner Plugin

Ironically, a plugin meant to scan for malware was itself vulnerable. Search Engine Journal confirmed this breach, highlighting the risk of trusting under-reviewed security tools.


Wordfence Launches Vulnerability Management Portal

Wordfence announced a powerful new portal designed to assist over 130 plugin developers with responsible vulnerability disclosure and patching. This centralized tool is expected to streamline communication between researchers and vendors. Read the launch post

SolidWP Reports 258 Vulnerabilities in July

SolidWP released two security reports this week:

Malicious Theme Redirects via Footer.php

Sucuri discovered threat actors injecting malicious redirects into the footer.php of WordPress themes, hijacking traffic to scam sites. Learn more here

Fake CAPTCHA Attacks

A malware campaign uncovered by MoeSecCom uses fake CAPTCHA popups to deliver payloads via compromised WordPress sites. It reinforces the need for advanced malware detection tools.


Developer Update: July 2025

@courtneyr_dev shared July’s developer update, focusing on REST API improvements, internationalization enhancements, and block pattern support.

Fueled’s WordPress Framework

Fueled released their internal WP Framework, designed to provide a stable scaffolding foundation for custom WordPress development. Read the release

WP User Frontend Update

weDevs added new controls in WPUF, including sorting for subscription plans and form layout improvements.


WordCamp US 2025 News

@pootlepress announced a WordPress portfolio workshop to be held at WordCamp US 2025. Additionally, @harsh98trivedi reminded applicants about the Kim Parsell Scholarship.

Tumblr’s Migration Delayed

The Verge revealed that Tumblr’s much-anticipated migration to WordPress and Fediverse integration is now on hold, due to technical complexity and strategic realignment.




This week reminds us that the WordPress ecosystem-while powerful-is also a massive target. From high-severity plugin CVEs to supply chain compromises, it’s crucial to keep core, plugins, and themes up to date and practice smart security hygiene. For a comprehensive approach to website protection, explore our guide on zero trust security models for web applications.

For more from this month, see our WordPress July 2025 recap covering the full month’s highlights. Let us know which stories you’d like us to explore in depth next week!


No comments yet