What matters now - all stories
72 stories
WooCommerce 11.0.1 is out: security fixes for checkout, Store API, and guest sessions
WooCommerce 11.0.1 is a security update with fixes for checkout, Store API, guest sessions, permissions, and WordPress 7.1 compatibility.…
BdThemes supply chain compromise: WordPress admins should check affected sites now
Wordfence reports a BdThemes supply chain compromise using poisoned JSON in wp-admin. Check affected plugins, admin users, webshells, and…
UK shipping changes: WooCommerce stores selling to the EU need a customs and checkout audit
WooCommerce highlights UK shipping changes that can affect EU delivery costs, customs clearance, DDU/DDP checkout setup, and returns. […]…
WordPress 7.0.3 fixes security issues – update your site now
WordPress 7.0.3 is a security release with fixes for XSS, SSRF, privilege escalation, and information disclosure issues. […] Read More… f…
Stripe for WooCommerce security update: check your version and test checkout
WooCommerce released a Stripe for WooCommerce security update. Stores on versions 9.7.0-10.8.4 should update and test checkout. […] Read …
WooCommerce Newsletter Causes Brief Site Outage – What You Should Know
WooCommerce faced a short outage after sending a newsletter to 800,000 recipients, highlighting risks of large email sends for site perfo…
Wordfence Bug Bounty Report: April 2026 Highlights Vulnerabilities and Rewards
In April 2026, the Wordfence Bug Bounty Program reported 1288 vulnerabilities, emphasizing community-driven security efforts in WordPress…
WordPress Week 31/2026: Update Security, WooCommerce 11.0 and WordPress 7.1 Testing
Week 31/2026 highlights: possible security patch delays, a WooCommerce 11.0 action timing change, and WordPress 7.1 Beta 4 testing guidan…
WooCommerce Security: Early Detection is Key to Protecting Your Store
New guidelines emphasize the importance of early detection of security issues in WooCommerce stores. Regular monitoring can significantly…
Protect The Shire may delay urgent WordPress plugin security fixes
Patchstack says WordPress.org’s update delay helps with supply-chain risk, but may slow urgent plugin security fixes. […] Read More… from…
Critical WordPress Security Vulnerability: Immediate Update Required!
A critical vulnerability in WordPress allows unauthenticated attackers to create admin accounts. Site owners must update immediately to a…
WordPress Hosting Security: Testing Reveals Gaps Between Claims and Reality
New podcast episode reveals that many WordPress hosting providers fail to deliver on security promises, risking site vulnerabilities. […]…