WordPress.org update API adds automated plugin review and high-risk release blocking
Security Tool/Service
Summary
Hide ▲
Show ▼
WordPress.org update API is adding an automated security review that can block high-risk plugin releases before they reach users, reducing the chance that malicious or vulnerable updates are distributed downstream. The rollout combines AI models and Jetpack Scan to score releases, then stops those above the risk threshold. It also formalizes a six-hour cooldown before auto-updates, tightening control over plugin distribution.
Related Happenings
Creative Mail plugin SQL injection SQL injection flaw (CVE-2026-3985)
Vulnerability
H score50
First: 15.07.2026 17:01
Last: 15.07.2026 17:01
Sources 1
About this happening:
A SQL injection flaw in the Creative Mail plugin exposes database read access, including admin hashes and secret tokens. The issue is tracked as CVE-2026-398...
Creative Mail plugin SQL injection SQL injection flaw (CVE-2026-3985)
VulnerabilityAbout this happening: A SQL injection flaw in the Creative Mail plugin exposes database read access, including admin hashes and secret tokens. The issue is tracked as CVE-2026-398...
Funnel Builder security patch release (version 3.15.0.3)
Security Patch Release
H score77
First: 16.05.2026 18:20
Last: 16.05.2026 18:20
Sources 1
About this happening:
FunnelKit released version 3.15.0.3 to fix a Funnel Builder flaw that was being actively exploited to inject malicious JavaScript into WooCommerce checkout pages...
Funnel Builder security patch release (version 3.15.0.3)
Security Patch ReleaseAbout this happening: FunnelKit released version 3.15.0.3 to fix a Funnel Builder flaw that was being actively exploited to inject malicious JavaScript into WooCommerce checkout pages...
Timeline
-
14.09.2026 19:00 1 articles · 3h ago
WordPress launches Protect The Shire cooldown for plugin and theme auto-updates
Mitigation Patch UpdateSince June 5, 2026, every WordPress plugin and theme has been placed into a cooldown period before auto-updates, part of Protect The Shire's effort to add friction so malicious updates do not reach users immediately.
Show sources
- WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution — thehackernews.com — 14.09.2026 19:00
-
14.09.2026 19:00 1 articles · 3h ago
Automated review detects a backdoor in a plugin release with about 20,000 installations
Detection Ioc UpdateWordPress's automated review detects a backdoor committed to a plugin release with about 20,000 active installations on July 28, 2026, and the compromised version never gets distributed through the WordPress.org update API because it remains inside the cooldown window.
Show sources
- WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution — thehackernews.com — 14.09.2026 19:00
-
14.09.2026 19:00 2 articles · 3h ago
WordPress announces automated security review for every plugin release
Initial DisclosureWordPress announces an automated security review for every plugin release before distribution through the WordPress.org update API, adding a consistent review step meant to analyze releases for vulnerabilities or malicious code.
Show sources
- WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution — thehackernews.com — 14.09.2026 19:00
- WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution — thehackernews.com — 14.09.2026 19:00