Core security release

WordPress 7.1.1 fixes 11 security bugs, plus a new default theme

WordPress 7.1.1 is a security release, so update. Plus a look at what is coming in 7.2, a new default theme called Ipsum and a small WooCommerce security update.

The big one this week: WordPress 7.1.1 came out on Thursday with 11 security fixes, so get your sites updated. WooCommerce shipped a small security update two days later.

The rest of the week was about what's coming next. WordPress 7.2 is due in December, there's a proposed new default theme, and the project has changed its mind about how collaborative editing should work.

WordPress 7.1.1 is a security release, so update

WordPress 7.1.1 landed on 17 September with 11 security fixes, 17 bug fixes in WordPress itself and 19 in the editor.1 Most sites have automatic updates for releases like this, so you may already be on it. It's worth checking under Dashboard › Updates rather than assuming. The fixes are also being backported to older versions, all the way back to 4.7.

Nothing here is being attacked as far as anyone has reported, and most of the fixes need someone to already have an account on your site. Two stand out anyway.

The first is a chain that Patchstack has nicknamed Click2Shell.2 An attacker crafts a link and gets a logged-in administrator to click it. That silently installs a theme from the WordPress.org directory, and a second link previews the theme, which is enough to run its code. The theme they chose has a flaw that lets an attacker install a plugin of their choosing from anywhere. The end result is a site takeover from one click. It needs a specific admin to click a specific link, so it isn't a drive-by, but it's a good reminder that admin accounts are the target.

The second is more of a sign of the times. Two of the 11 fixes were reported by Anthropic, the AI company. That's the same pattern as the Core Security Initiative a few weeks ago: AI tools are now a real source of WordPress security reports.

One more thing worth knowing if you run a multisite network. 7.1.1 fixes the bug I mentioned last week where deleting a user could skip the "who gets their posts?" step and delete their content. You can stop being careful now.

WordPress news

WordPress 7.2 is due in early December

The roadmap is out.3 Two things caught my eye.

There's a "sudo mode", which asks you to re-enter your password before doing something sensitive in the admin area. Banks have done this for years and it's a sensible defence against exactly the kind of attack Click2Shell used.

The Secrets API is also on the list, which is the proper encrypted store for API keys proposed last month. Good to see it move along.

For editors, Notes are getting suggestion mode, so you can propose an edit for someone else to accept or reject, along with emoji reactions.

Ipsum is the proposed new default theme

The next default theme is called Ipsum, and it's a deliberately plain blogging theme meant as a blank canvas.4 The bigger news is the name. After sixteen years of Twenty Ten, Twenty Eleven and so on, default themes will now get real names, on Matt Mullenweg's direction. It's proposed for 7.2 and it's on GitHub if you want to try it.

Collaborative editing is being rebuilt

Real-time collaboration was pulled from WordPress 7.0, and the team has now explained what went wrong and what happens next.5 The current version merges everyone's edits in the browser, which means the server can't tell who wrote what.

That's a security problem, not just a technical one. The post gives a good example: an author who isn't allowed to publish raw HTML works on a post with an admin, slips a script into a block, and when the admin saves, the server treats the whole post as the admin's work. The new approach makes the server a participant, so it can check who did what.

Gutenberg 24.0

Visual revisions now cover the post title, so you can see when a post was renamed.6 The Gallery block gets a proper grid layout with different column counts per screen size, which removes a common reason for custom CSS.

Around the community

Automattic staff still don't know what happened

A week after Automattic's board briefly removed Matt Mullenweg as CEO, employees say they still haven't been told why, and have learned what they know from the press.7

TechCrunch reports that during the 33 hours Mullenweg was on leave, the interim CEO and the chief legal officer signed each other's severance agreements, worth a combined $8.15 million, based on documents it reviewed.8 Both were let go when Mullenweg returned. Automattic hasn't commented.

None of this changes anything for your site. It's a reminder that the company funding much of WordPress is going through something, and it isn't over yet.

WooCommerce

WooCommerce 11.1.1 is a security update

11.1.1 arrived on 18 September with tighter checks on API permissions, authentication and guest sessions, plus a fix for mini cart styling when the block is hidden.9 There's no database update this time, so it's a straightforward one. Update when you can.

Purple, an official Woo block theme

Woo's own block theme is back from the dead and ready for beta testing.10 It's a starter theme with templates for the block-based store pages, ten colour palettes and a library of ecommerce patterns. It's on GitHub now, and it's heading for the theme directory once testing is done. Worth a look if you're planning a new store build.

Plugin security updates

A quieter week for plugins, mostly because WordPress itself took the spotlight.

Wholesale Lead Capture is under attack

Wordfence has the details on the attacks.11 It also published the full write-up behind last week's Tutor LMS fix, which is worth a read if you run a course site. Updating to 4.0.8 or later still covers it.12

The image library behind your uploads

This one isn't a WordPress plugin, but it may affect your server. libheif, the library many servers use to handle iPhone photos, had a critical bug that a crafted HEIC image could use to read files or run code on the server.13 It's fixed in libheif 1.23.3.

There's nothing to update in WordPress. The fix comes from your operating system or your host. Wordfence tested nine setups and found the official WordPress Docker image among the vulnerable ones, so if you run containers, rebuild from an updated base image. If your site accepts image uploads from the public, it's a fair question to put to your host.

For the long tail, Wordfence's latest weekly report counted 260 vulnerabilities across 207 plugins in the week to 13 September.14

What I'd do this week

  • Update WordPress to 7.1.1, today. Check Dashboard › Updates to be sure it has actually gone through.
  • Update WooCommerce to 11.1.1. It's a security release, and there's no database update to worry about.
  • Selling wholesale? Check Wholesale Lead Capture is on 2.0.3.2 or later.
  • Ask your host about libheif if your site takes image uploads from visitors, or rebuild your containers if you run your own.
  • Multisite on 7.1? Once you're on 7.1.1, you can go back to deleting users normally.

Would you rather someone else kept on top of this?

My maintenance plans cover updates, security monitoring, backups and priority support, so weeks like this one are handled for you. If something has already gone wrong, emergency support starts from £50 with a fixed quote upfront.