Active attacks

WordPress core bug under attack, plus Elementor and WPForms fixes

Attackers started using a serious WordPress bug within hours of the 7.1.2 fix, so update today. Plus Elementor, WPForms and WooCommerce fixes.

One job comes before everything else this week: make sure your sites are on WordPress 7.1.2. It fixes a serious bug in WordPress itself, and attackers were trying it on sites the same day it came out.

Elsewhere, Elementor had to fix a nasty bug in a two-day-old release, and a judge brought WP Engine's antitrust case against Automattic back to life.

Attackers are already using the bug fixed in 7.1.2

WordPress 7.1.2 landed on 22 September with one fix, for a critical bug in every version back to 4.7.1 Anyone, without logging in, could trick WordPress into loading a PHP file from elsewhere on the server. On some setups, that's enough to take over the site.

Two things have to line up for that.2 Your theme needs a top-level folder whose name starts with "page-", and the advisory names Twenty Twelve, Twenty Fourteen, Neve, Hestia and Sydney as examples. And the server needs a PHP setup that comes as standard with cPanel on PHP versions before 8.5, which covers a lot of shared hosting.

Patchstack saw the first attempts on release day, and within hours some attackers were using the bug to write their own files onto servers.3 A ready-made scanning tool is now doing the rounds, and on Friday CISA, the US government's cyber security agency, added the bug to its list of ones known to be under attack.4 Honestly, it's the first WordPress core bug in years that I'd call a drop-everything update.

The fix has been backported to older versions too (7.0.6, 6.9.9, 6.8.10 and so on), and most sites install these by themselves. Don't lean on a free firewall plugin, because Wordfence's rule for this only reaches free users on 22 October.5

If a site sat on an older version for part of the week and uses one of those themes, ask your host to check the server's temporary folders for PHP files nobody recognises. That's where attackers have been leaving them.3 If anything turns up, follow my guide to cleaning up a hacked site.

WordPress news

WordPress now leads the Open Website Alliance

Mary Hubbard now represents the WordPress Foundation as president of the Open Website Alliance, the open source group WordPress shares with Drupal, Joomla and TYPO3.6 The role rotates between members, who first worked together on a response to the EU's Cyber Resilience Act.

For developers

There's now an MCP server for WordPress Trac, so AI assistants can read tickets and changesets.7

Around the community

A judge has revived WP Engine's antitrust claims

The judge in WP Engine's lawsuit against Automattic and Matt Mullenweg threw out its antitrust claims a year ago, and on 24 September she reversed that.8 WP Engine can now argue that Automattic used its control of WordPress.org to squeeze competitors, including over hosting and custom field plugins like ACF. Most of the trademark counterclaims against WP Engine survive too.9

Nothing changes for your site, but this case has a long way to run.

Automattic has a new board

Just over two weeks after Automattic's board tried to put Matt Mullenweg on leave, there's a new board. TechCrunch reports three departures and four new members, including the novelist Hugh Howey.10 Mullenweg controls 84% of the voting shares, which is how he could rebuild it so quickly.

Google's translate widget loses support on 1 October

Google's Website Translator widget, the old "Select Language" dropdown, won't be supported from 1 October.11 Google announced it in a note on an old blog post at the start of September, so it's easy to have missed. It may keep working for a while, but if you use it, I'd plan a replacement now.

WooCommerce

WooCommerce 11.1.2 is another security update

11.1.2 arrived on 22 September, four days after 11.1.1.12 It tightens security around email-based product reviews and fixes a bug that could break product pages with variations on some themes. There's no database update.

WooCommerce 11.2 is due the week of 6 October

The beta is out.13 My favourite change is a small one: the product importer can now match existing products by barcode (GTIN, UPC, EAN or ISBN) when there's no ID or SKU.

Two things to watch. Stacked coupons with sequential discounts will apply in the order the customer entered them, which can shift totals. And the Cart and Checkout blocks get a fixed-width order summary, so check any custom styling there. There's a database update, so back up first.

Plugin security updates

Elementor fixed a one-click takeover bug

In Elementor 4.3.0 and 4.3.1, released on 22 and 23 September, a logged-in administrator who clicked a specially crafted link could unknowingly create a new admin account for whoever sent it.14 The link could come by email, in a chat or in a comment.

4.3.2 fixed it on 24 September. Nobody has reported attacks, but Elementor runs on more than 10 million sites, so if yours updated on 22 or 23 September, check it's now on 4.3.2.

Other updates worth doing

If you use any of these, update this week:15

Plugin Sites What's wrong Fixed in Action
WPForms 5M+ Anyone could refund or cancel Stripe payments your other tools took 2.0.2.1 Update
Gravity Forms 1M+ Anyone could upload files that run code, if a form has a hidden upload field After 3.1.0.4 Update now
File Manager 1M+ Anyone could download its database backups on some servers 8.0.5 Update
Forminator 600,000+ Anyone could make your site run shortcodes it shouldn't 1.57.2.1 Update
Ninja Forms 600,000+ Anyone could hide harmful code in a form entry for an admin to open 3.15.4 Update
TranslatePress 400,000+ Anyone could plant harmful code that runs in the translation editor 3.3.6 Update
Ultimate Member 200,000+ Anyone who signs up could hide harmful code in their profile name 2.13.1 Update
HUSKY Products Filter 80,000+ Anyone could make your site run other files on the server 1.4.5 Update now
Customer Reviews for WooCommerce 80,000+ Anyone with a review link could delete images from your media library 5.121.0 Update
Bookly 60,000+ Anyone could see other customers' bookings and delete them 28.3 Update
WP Recipe Maker 50,000+ Anyone could stuff an account with data until it stops loading, admins included 10.8.2 Update

Gravity Forms, Forminator and Ultimate Member were disclosed on 17 and 18 September, just too late for last week. Gravity Forms updates from its own server rather than WordPress.org, so check it's on 3.1.2, the latest.16 If WPForms shares a Stripe account with anything else, update it first.17 And any visitor can reach the HUSKY bug, so don't leave that one.

Meta Box AIO, a paid bundle, had a bug that could let anyone make themselves an administrator. Update to 3.12.0 or later.18 AMP for WP (1.1.17), FileOrganizer (1.2.1), Profile Builder (4.0.3), WPC Product Bundles (8.6.7) and Zero Spam (5.7.11) also fixed bugs that let anyone plant harmful code for an admin to trip over. If you're not sure how to handle any of this, see my guide to dealing with a plugin security vulnerability.

No fix yet for Request a Quote for WooCommerce

Addify's Request a Quote for WooCommerce, a paid extension on about 5,000 stores, has a bug that lets anyone upload files that can run code, if a quote rule uses its multi-page popup form.19 Wordfence disclosed it on Friday, and the latest version (2.9.2) is still affected. If you use that popup, switch it off or deactivate the plugin until Addify ships a fix.

Malware that hides from your dashboard

Wordfence published a teardown of malware it keeps finding in clean-ups.20 It hides itself from the Plugins screen and adds an admin account that it hides from the Users screen too. Then it records admin passwords and copies WooCommerce orders and payment keys. Delete it and it puts itself back.

So a clean-looking dashboard doesn't prove a clean site. If you suspect a hack, start with my hacked site guide, and if a shop is affected, ask your payment provider about replacing your keys.

For the long tail, Wordfence's report for 14 to 20 September counted 358 new vulnerabilities across 243 plugins and 4 themes.21

What I'd do this week

  • Update WordPress to 7.1.2 (or your version's security release) today, then check Dashboard › Updates to make sure it happened.
  • Ask your host for a quick check if a site ran an older version this week with one of the themes above. If they find anything odd, follow the hacked site guide.
  • Update Elementor to 4.3.2, then your form plugins. WPForms, Gravity Forms, Ninja Forms and Forminator all had serious fixes.
  • Update WooCommerce to 11.1.2, and try 11.2 on a staging site before 6 October. If an update breaks something, here's how to fix a site after a bad update.
  • Using Addify's Request a Quote? Switch off its popup quote form until there's a fix.
  • Using Google's translate dropdown? Plan a replacement.

  1. WordPress 7.1.2 Release, WordPress.org, 22 September 2026. ↩

  2. Unauthenticated path traversal in page-template resolution leading to conditional RCE, WordPress Security Team, 22 September 2026. ↩

  3. CVE-2026-87902: Attackers Started Probing WordPress Sites Hours After the Patch, Patchstack, 22 September 2026, updated 23 September 2026. ↩ ↩

  4. Known Exploited Vulnerabilities Catalog, CISA, 25 September 2026. ↩

  5. PSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core, Wordfence, 22 September 2026. ↩

  6. WordPress Takes Its Turn Leading the Open Website Alliance, WordPress.org, 21 September 2026. ↩

  7. WordPress Trac MCP server, Make WordPress Core, 24 September 2026. ↩

  8. WP Engine's Antitrust Claims Against Automattic Are Back On After Judge Reverses Earlier Dismissal, The Repository, 25 September 2026. ↩

  9. Order re motions to dismiss, WPEngine, Inc. v. Automattic Inc., No. 24-cv-06917-AMO, US District Court for the Northern District of California, 24 September 2026. ↩

  10. Automattic has a new board after failed attempt to put CEO on leave, TechCrunch, 25 September 2026. ↩

  11. Google Translate's Website Translator - available for non-commercial use, Google Search Central Blog, updated 1 September 2026. ↩

  12. WooCommerce 11.1.2 Release Notes, WooCommerce Developer Blog, 22 September 2026. ↩

  13. WooCommerce 11.2.0 Pre-release notes, WooCommerce Developer Blog, 21 September 2026. ↩

  14. Cross-Site Request Forgery in Elementor Plugin Affecting 2 Million+ Sites, Patchstack, 25 September 2026. Fix confirmed in the plugin's changelog on WordPress.org. ↩

  15. Wordfence Intelligence vulnerability database, Wordfence, and WPScan for WPForms, File Manager, Ultimate Member and WP Recipe Maker. Fixed versions checked against each plugin's changelog. ↩

  16. CVE-2026-84434, NIST National Vulnerability Database, 19 September 2026. Latest version checked against the Gravity Forms change log. ↩

  17. WPForms Lite 1.8.8.2 to 2.0.1.1: Unauthenticated Stripe Refund and Subscription Cancellation via External PaymentIntent, WPScan, 22 September 2026. ↩

  18. CVE-2026-13355, NIST National Vulnerability Database, 22 September 2026. Fix confirmed in the Meta Box AIO changelog. ↩

  19. CVE-2026-18143, NIST National Vulnerability Database, 26 September 2026. Latest version checked on the WooCommerce.com product page. ↩

  20. Inside a Malicious, Stealthy WordPress Must Use Plugin, Wordfence, 22 September 2026. ↩

  21. Wordfence Intelligence Weekly WordPress Vulnerability Report, 14 to 20 September 2026, Wordfence, 24 September 2026. ↩

Would you rather someone else kept on top of this?

My maintenance plans cover updates, security monitoring, backups and priority support, so weeks like this one are handled for you. If something has already gone wrong, emergency support starts from £50 with a fixed quote upfront.