Find notable cyber news and cases, enriched with sources, timelines, and signals.

WordPress.org update API adds automated plugin review and high-risk release blocking

Security Tool/Service
First reported
Last updated
Happening score
H score 16
1 unique sources, 1 articles

Summary

Hide ▲

WordPress.org update API is adding an automated security review that can block high-risk plugin releases before they reach users, reducing the chance that malicious or vulnerable updates are distributed downstream. The rollout combines AI models and Jetpack Scan to score releases, then stops those above the risk threshold. It also formalizes a six-hour cooldown before auto-updates, tightening control over plugin distribution.

Related Happenings

Creative Mail plugin SQL injection SQL injection flaw (CVE-2026-3985)

Vulnerability
H score50 First: 15.07.2026 17:01 Last: 15.07.2026 17:01 Sources 1

About this happening: A SQL injection flaw in the Creative Mail plugin exposes database read access, including admin hashes and secret tokens. The issue is tracked as CVE-2026-398...

Funnel Builder security patch release (version 3.15.0.3)

Security Patch Release
H score77 First: 16.05.2026 18:20 Last: 16.05.2026 18:20 Sources 1

About this happening: FunnelKit released version 3.15.0.3 to fix a Funnel Builder flaw that was being actively exploited to inject malicious JavaScript into WooCommerce checkout pages...

Timeline

  1. 14.09.2026 19:00 1 articles · 3h ago

    WordPress launches Protect The Shire cooldown for plugin and theme auto-updates

    Mitigation Patch Update

    Since June 5, 2026, every WordPress plugin and theme has been placed into a cooldown period before auto-updates, part of Protect The Shire's effort to add friction so malicious updates do not reach users immediately.

    Show sources
  2. 14.09.2026 19:00 1 articles · 3h ago

    Automated review detects a backdoor in a plugin release with about 20,000 installations

    Detection Ioc Update

    WordPress's automated review detects a backdoor committed to a plugin release with about 20,000 active installations on July 28, 2026, and the compromised version never gets distributed through the WordPress.org update API because it remains inside the cooldown window.

    Show sources
  3. 14.09.2026 19:00 2 articles · 3h ago

    WordPress announces automated security review for every plugin release

    Initial Disclosure

    WordPress announces an automated security review for every plugin release before distribution through the WordPress.org update API, adding a consistent review step meant to analyze releases for vulnerabilities or malicious code.

    Show sources