WordPress 7.1.1 fixes 11 security bugs, plus a new default theme
WordPress 7.1.1 is a security release, so update. Plus a look at what is coming in 7.2, a new default theme called Ipsum and a small WooCommerce security update.
The big one this week: WordPress 7.1.1 came out on Thursday with 11 security fixes, so get your sites updated. WooCommerce shipped a small security update two days later.
The rest of the week was about what's coming next. WordPress 7.2 is due in December, there's a proposed new default theme, and the project has changed its mind about how collaborative editing should work.
WordPress 7.1.1 is a security release, so update
WordPress 7.1.1 landed on 17 September with 11 security fixes, 17 bug fixes in WordPress itself and 19 in the editor.1 Most sites have automatic updates for releases like this, so you may already be on it. It's worth checking under Dashboard › Updates rather than assuming. The fixes are also being backported to older versions, all the way back to 4.7.
Nothing here is being attacked as far as anyone has reported, and most of the fixes need someone to already have an account on your site. Two stand out anyway.
The first is a chain that Patchstack has nicknamed Click2Shell.2 An attacker crafts a link and gets a logged-in administrator to click it. That silently installs a theme from the WordPress.org directory, and a second link previews the theme, which is enough to run its code. The theme they chose has a flaw that lets an attacker install a plugin of their choosing from anywhere. The end result is a site takeover from one click. It needs a specific admin to click a specific link, so it isn't a drive-by, but it's a good reminder that admin accounts are the target.
The second is more of a sign of the times. Two of the 11 fixes were reported by Anthropic, the AI company. That's the same pattern as the Core Security Initiative a few weeks ago: AI tools are now a real source of WordPress security reports.
One more thing worth knowing if you run a multisite network. 7.1.1 fixes the bug I mentioned last week where deleting a user could skip the "who gets their posts?" step and delete their content. You can stop being careful now.
WordPress news
WordPress 7.2 is due in early December
The roadmap is out.3 Two things caught my eye.
There's a "sudo mode", which asks you to re-enter your password before doing something sensitive in the admin area. Banks have done this for years and it's a sensible defence against exactly the kind of attack Click2Shell used.
The Secrets API is also on the list, which is the proper encrypted store for API keys proposed last month. Good to see it move along.
For editors, Notes are getting suggestion mode, so you can propose an edit for someone else to accept or reject, along with emoji reactions.
Ipsum is the proposed new default theme
The next default theme is called Ipsum, and it's a deliberately plain blogging theme meant as a blank canvas.4 The bigger news is the name. After sixteen years of Twenty Ten, Twenty Eleven and so on, default themes will now get real names, on Matt Mullenweg's direction. It's proposed for 7.2 and it's on GitHub if you want to try it.
Collaborative editing is being rebuilt
Real-time collaboration was pulled from WordPress 7.0, and the team has now explained what went wrong and what happens next.5 The current version merges everyone's edits in the browser, which means the server can't tell who wrote what.
That's a security problem, not just a technical one. The post gives a good example: an author who isn't allowed to publish raw HTML works on a post with an admin, slips a script into a block, and when the admin saves, the server treats the whole post as the admin's work. The new approach makes the server a participant, so it can check who did what.
Gutenberg 24.0
Visual revisions now cover the post title, so you can see when a post was renamed.6 The Gallery block gets a proper grid layout with different column counts per screen size, which removes a common reason for custom CSS.
Around the community
Automattic staff still don't know what happened
A week after Automattic's board briefly removed Matt Mullenweg as CEO, employees say they still haven't been told why, and have learned what they know from the press.7
TechCrunch reports that during the 33 hours Mullenweg was on leave, the interim CEO and the chief legal officer signed each other's severance agreements, worth a combined $8.15 million, based on documents it reviewed.8 Both were let go when Mullenweg returned. Automattic hasn't commented.
None of this changes anything for your site. It's a reminder that the company funding much of WordPress is going through something, and it isn't over yet.
WooCommerce
WooCommerce 11.1.1 is a security update
11.1.1 arrived on 18 September with tighter checks on API permissions, authentication and guest sessions, plus a fix for mini cart styling when the block is hidden.9 There's no database update this time, so it's a straightforward one. Update when you can.
Purple, an official Woo block theme
Woo's own block theme is back from the dead and ready for beta testing.10 It's a starter theme with templates for the block-based store pages, ten colour palettes and a library of ecommerce patterns. It's on GitHub now, and it's heading for the theme directory once testing is done. Worth a look if you're planning a new store build.
Plugin security updates
A quieter week for plugins, mostly because WordPress itself took the spotlight.
Wholesale Lead Capture is under attack
Wordfence has the details on the attacks.11 It also published the full write-up behind last week's Tutor LMS fix, which is worth a read if you run a course site. Updating to 4.0.8 or later still covers it.12
The image library behind your uploads
This one isn't a WordPress plugin, but it may affect your server. libheif, the library many servers use to handle iPhone photos, had a critical bug that a crafted HEIC image could use to read files or run code on the server.13 It's fixed in libheif 1.23.3.
There's nothing to update in WordPress. The fix comes from your operating system or your host. Wordfence tested nine setups and found the official WordPress Docker image among the vulnerable ones, so if you run containers, rebuild from an updated base image. If your site accepts image uploads from the public, it's a fair question to put to your host.
For the long tail, Wordfence's latest weekly report counted 260 vulnerabilities across 207 plugins in the week to 13 September.14
What I'd do this week
- Update WordPress to 7.1.1, today. Check Dashboard › Updates to be sure it has actually gone through.
- Update WooCommerce to 11.1.1. It's a security release, and there's no database update to worry about.
- Selling wholesale? Check Wholesale Lead Capture is on 2.0.3.2 or later.
- Ask your host about libheif if your site takes image uploads from visitors, or rebuild your containers if you run your own.
- Multisite on 7.1? Once you're on 7.1.1, you can go back to deleting users normally.
WordPress 7.1.1 Maintenance and Security Release, WordPress.org, 17 September 2026. ↩
Click2Shell: The RCE WordPress 7.1.1 Just Patched, Patchstack, 18 September 2026. ↩
Roadmap to 7.2, Make WordPress Core, 18 September 2026. ↩
Introducing Ipsum, the new default theme, Make WordPress Core, 16 September 2026. ↩
Moving to a server-aware approach for collaboration, Make WordPress Core, 18 September 2026. ↩
What's new in Gutenberg 24.0, Make WordPress Core, 16 September 2026. ↩
One Week After Board Crisis, Automattic Employees Say They're Being Kept in the Dark, The Repository, 18 September 2026. ↩
Automattic's interim CEO and legal chief signed reciprocal severance deals during Mullenweg's brief ouster, TechCrunch, 16 September 2026. ↩
WooCommerce 11.1.1 Release Notes, WooCommerce Developer Blog, 18 September 2026. ↩
Call for testing: Purple, a WooCommerce block theme, WooCommerce Developer Blog, 15 September 2026. ↩
Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin, Wordfence, 14 September 2026. ↩
100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection in Tutor LMS, Wordfence, 17 September 2026. ↩
Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server, Wordfence, 18 September 2026. ↩
Wordfence Intelligence Weekly WordPress Vulnerability Report, 7 to 13 September 2026, Wordfence, 17 September 2026. ↩