WordPress Security Overhaul, WooCommerce 11.1, and CMS Conf

WordPress Security Overhaul, WooCommerce 11.1, and CMS Conf
View on original source
Category: SciTech
Share
Archive
Like
This issue of WP More is brought to you by our sub-reddit;join now and start a WordPress discussion today! Hello WordPressers! Welcome to this week'sWP Moreroundup. This is WP More newsletter issue 55,where you get curated news about WordPress and the WordPress community all in one place. Security is getting a serious upgrade this week, WooCommerce 11.1 ships faster APIs and native variation galleries, Miriam Schwab calls out the gap between WordPress core's AI plumbing and what the plugin ecosystem is actually delivering, and a Polish organizing team just launched a cross-platform CMS conference to break out of the WordPress bubble. Thanks for reading WP More!! Subscribe for free to receive new posts and support my work. The WordPress Core Security Initiative: A Response to AI-Driven Vulnerabilities WooCommerce 11.1: Faster APIs, Variation Galleries, and More WordPress Is Ready for the Agentic Web, but the Ecosystem Isn't 31 WordCamps Later: One Contributor's Experience in Phoenix Polish WordCamp Organizers Launch CMS Conf, a New Cross-Platform Conference AI-powered security research is flooding WordPress's bug bounty inbox. Monthly reports to the HackerOne program held steady at 20-30 for a decade, then jumped to 450 in July and hit 773 in August alone.The WordPress Security Team has responded with the Core Security Initiative, a coordinated effort built around three pillars: a tighter, more automated release process for fixes; a push to clear the backlog of open reports by bringing on more volunteers; and AI-assisted scanning to catch vulnerabilities before they get reported at all. The scope of the HackerOne program has also been tightened.Vulnerabilities that require an administrator-granted role, like Contributor, will generally no longer qualify unless they demonstrate a high-severity escalation. Bugs where one authenticated role does something normally available to another won't be enough on their own. If you do find something, report it at hackerone.com/wordpress and review the updated guidelines first. Read the full blog on Making WordPress Secure → Security is just one part of what's been a busy few weeks for WordPress. The WooCommerce team has been shipping too. WooCommerce 11.1, released September 1, brings a real speed bump alongside features store owners have been waiting on. The headline change: Store API and REST requests are now 30-42% faster, by skipping block registration on requests that don't need it. No code changes required on your end. Variation image galleries are now a native WooCommerce feature, with no extra extension needed.The Additional Variation Images plugin is being retired, and the gallery is on by default for all stores. Virtual-only orders no longer show a shipping address in admin, clearing up display clutter that served no purpose. Video support in product galleries lands in beta, disabled by default, for locally uploaded videos. Developers also get a unified block editor asset system as an experimental feature, and a fix toremove_order_items()that stops replacement items from being accidentally deleted on save. Read the full blog on The WooCommerce Developer Blog → While WooCommerce ships performance wins, one WordPress voice is asking harder questions about what the platform still needs to deliver for the next wave of the web. Miriam Schwab gave a talk at WordCamp US called 'The Agentic Web Is Coming: Is WordPress Ready?' Core has the plumbing, she found. The plugin ecosystem hasn't shown up. WordPress since version 7 ships the Abilities API and the MCP Adapter, giving agents a defined way to interact with a site. But core only registers three abilities out of the box. On Miriam's own site, 67 abilities are registered. Three come from core. She built 41 herself.She also tested whether agent-ready features like llms.txt and markdown page versions were being used. They mostly weren't. Claude went straight for the HTML and converted it to markdown itself, ignoring the dedicated files. Bots want what humans want. Clean semantics, stable URLs, structured data, markup without junk. Build for people and agents follow. Read the full blog on MiriamSchwab.me → The plugin ecosystem gap Miriam describes was a real conversation topic at WordCamp US itself, where contributors gathered for four days in Phoenix. Brought to you by I send this newsletter every week, but do you want to keep up with WordPress and the community? Then follow WP More's social profile. X (formerly Twitter) -https://x.com/WPMoree LinkedIn -https://www.linkedin.com/company/wordpress-more/ BlueSky -https://bsky.app/profile/wpmore.bsky.social I am always posting there every day. So, you are not going to miss anything. Follow WP More, Stay Updated with WordPress! Mainul Kabir Aion flew from Kuala Lumpur for his 31st WordCamp, this time also organizing on the Attendee Communications team. WordCamp US 2026 ran August 16-19 at the Phoenix Convention Center with 425 contributors on Day 1, including 29 first-timers across 26 teams. His highlight was a hackathon where his group built an AI-powered site architecture tool for service-area businesses, designed to map out which service pages to create, how they connect, and which thin pages to skip. They finished the day with a concrete workflow and pitched it as a rap. Beyond the hackathon, he scored 995 out of 1000 at the Community Booth quiz to take home a LEGO Wapuu, then spent an hour painting his own mascot.His post is an honest account of how much WordCamp work happens out of sight, and why that effort matters. Read the full blog on MKAion.com → WordCamp US wasn't the only community event making news this week. In Poland, a WordCamp organizing team is building something different entirely. The team behind WordCamp Gdynia has launched CMS Conf, a three-day conference for CMS creators and developers, scheduled November 12-14 in Gdynia, Poland. Lead organizer Maciek Palmowski said 15 years in WordPress left him with almost no picture of what was happening on the other 58% of the web. CMS Conf is the fix. The event received around 120 speaker submissions for roughly 30 slots, with talks covering WordPress, Drupal, Joomla, TYPO3, Astro, Payload, and Cloudflare's EmDash. Speakers are coming from Figma, the Drupal Association, Automattic, Cloudflare, and Zendesk. Two parallel tracks run, one for developers and one for creators, borrowed directly from the WordCamp format. The team had to form a company to run independently, since the WordPress Foundation only handles WordCamp finances. Tickets are €150 at cmsconf.com. Read the full blog on The Repository → →6 WordCamp US 2026 Sessions Worth Your Time (and What I Actually Took Away From Each) (wpmore.net) - WordCamp US 2026 had 60+ sessions. Most of them I won't remember in a week. These six stayed with me. →Security Stories from the People Who Experienced Real Incidents(melapress.com) - Melapress's Wall of Security Stories collects first-hand accounts of website hacks, their financial impact, and the recovery work that the vulnerability numbers never show. →WordPress Tightens Bug Bounty Scope After Monthly Security Reports Nearly Double to 773(therepository.email) - Reports to WordPress's HackerOne program jumped from a decade-long baseline of 20-30 a month to 773 in August alone, driven by AI-assisted security research tools. →Bringing Together Our Various Responsive Tooling(nomad.blog) - Anne McCarthy maps out the current state of WordPress responsive controls ahead of 7.2, covering fluid typography, viewport-based block visibility, and the gaps that still need solving. →Telex Has Been Retired(telex.automattic.ai) - Automattic's AI-assisted authoring environment for WordPress has been shut down. →Transparency Report Update: January – June 2026(transparency.automattic.com) - Automattic's mid-year transparency report covers content takedown requests, government demands, DSA compliance, and the difficult balance between user expression and reporter rights. →WordCamp US 2026 Contributor Day Recap(make.wordpress.org) - The Hosting team's write-up from Contributor Day in Phoenix, covering what the team worked on across 425 participants and 26 contributing teams. →Themes Team Update September 1, 2026(make.wordpress.org) - The latest weekly status update from the WordPress Themes team. →WordCamp US 2026: PHP Conversation(make.wordpress.org) - Notes from the PHP discussion held at WordCamp US, covering the project's approach to PHP version support and compatibility decisions. →Announcing the 2026 Kim Parsell Memorial Scholarship Recipient: Jeanherline Santiago(wordpressfoundation.org) - The WordPress Foundation names this year's scholarship recipient, awarded annually in memory of community contributor Kim Parsell. →Replacing Dashicons in the Admin Bar and Menu(make.wordpress.org) - A look at the ongoing effort to move WordPress admin icons away from the aging Dashicons icon font. →WordPress 7.1.1 Release Schedule(make.wordpress.org) - The core team has published the schedule for the upcoming 7.1.1 maintenance release. →AI Contributor Weekly Summary – 2 September 2026(make.wordpress.org) - The WordPress AI team's weekly summary covering contributor activity and progress in the AI working group. →Accessibility Team Meeting Notes: Aug 27, 2026(make.wordpress.org) - Notes from the WordPress Accessibility team's most recent meeting. →Agenda: Weekly Polyglots Chat – September 2, 2026 (7:00 UTC)(make.wordpress.org) - The agenda for the weekly Polyglots team chat, covering locale stats, the WordPress 7.1.1 release schedule, and open help and feedback items. →Emoji Locale (art-xemoji): How Would You Translate Weekdays and Months?(make.wordpress.org) - The Polyglots team opens a discussion on how to handle weekday and month names in the emoji locale, which has no spoken language to fall back on. →A Week in Openverse: 2026-08-24 – 2026-08-31(make.wordpress.org) - The Openverse team's weekly update covering development work and progress from the last week of August. →What's New in Gutenberg 23.9? (2 September)(make.wordpress.org) - A full rundown of the changes and improvements shipping in the latest Gutenberg release. →Updates to the WordPress Vulnerability Disclosure Program(make.wordpress.org) - The Security Team's formal update on the scope changes to the HackerOne disclosure program, with guidance for researchers on what now qualifies. →WooCommerce 11.1 Delivers Faster REST and Store API Requests by Skipping Block Registration(developer.woocommerce.com) - A deeper technical look at how WooCommerce 11.1 cuts Store API and REST response times by 30-42% by skipping block registration on non-rendering requests. →WordPress Announces Core Security Initiative as AI-Driven Vulnerability Reports Hit Record Levels(therepository.email) - The Repository's full coverage of the Core Security Initiative announcement, with context on the AI-assisted research surge driving the record report volumes. →WordCamp Belgrade Returns With a New Bilingual Format to Bring the Community Together(therepository.email) - WordCamp Belgrade is back and running both Serbian and English tracks to widen who can participate and benefit. →Aaron D Campbell on Navigating WordPress Security in the AI Era(wptavern.com) - WP Tavern's podcast episode with longtime WordPress security contributor Aaron D Campbell on what AI means for vulnerability research and the project's defenses. →WordPress Is Eating Itself Alive(youtube.com) - A candid video essay on the tensions inside the WordPress project and the community dynamics that have built up over recent years. →Why Real-Time WordPress Is the Future(thewpminute.com) - The WP Minute makes the case for real-time, collaborative WordPress editing and what needs to change for it to get there. →Enqueue Returns to Sydney to Explore What AI Means for WordPress Developers(therepository.email) - The Enqueue developer event is coming back to Sydney with AI and its practical implications for WordPress development as its central theme. WordPress's HackerOne inbox went from 450 reports in July to 773 in August, driven almost entirely by AI-assisted security research tools. That volume prompted a structural response: tighter scope rules on the bug bounty program, more volunteers to clear the backlog, and AI-assisted scanning to catch vulnerabilities before researchers do. Is your site's security posture keeping up with how fast the threat surface is changing? And if you're a developer, are you paying attention to what the scope changes mean for the reports you might submit? Hit reply with your take. If this issue was useful, pass it along. — Nishat, WP More Follow →X.com|LinkedIn|BlueSky|Facebook Join Our Community →Sub-Reddit|X Community Thanks for reading WP More! This post is public, so feel free to share it. Share

(0)Comments

 

A note on cookies

Newshunt uses essential cookies to keep you signed in and to remember your language and country, so the site works the way you expect. With your permission, we'd also like to use analytics cookies to understand how people use Newshunt and improve it over time.

Accepting only affects analytics. To learn more, view our Privacy Policy or Terms & Conditions.