WooCommerce sets a PHP 8.1 date, EmDash 1.0 and an UpdraftPlus fix
WooCommerce will need PHP 8.1 from February 2027, Cloudflare launched EmDash 1.0 and UpdraftPlus, All in One SEO and Ultimate Member fixed security bugs.
A calmer week after last week's scramble. If any of your sites still aren't on WordPress 7.1.2, last week's issue explains why that comes first.
The main news is for shop owners: WooCommerce has set a firm date for needing PHP 8.1. Cloudflare's EmDash also reached 1.0, and there's a long list of plugin fixes, with UpdraftPlus and All in One SEO among them.
WooCommerce will need PHP 8.1 from February
It's official. WooCommerce 11.6, planned for February 2027, will need PHP 8.1 or newer.1 That's one release later than the January date floated last month, pushed back after feedback so stores can make the change after the Christmas rush.
From 11.3, stores on PHP 7.4 or 8.0 will see a notice in the admin area. Nothing breaks. You just won't be offered WooCommerce 11.6 until your PHP is upgraded, and 11.5 is the last version that runs on the older ones. If you stay on 11.5, only the most serious security fixes will reach you. About 9% of the stores WooCommerce tracks are still on PHP 7.4 or 8.0.
My advice matches WooCommerce's. Check your PHP version under WooCommerce › Status, then ask your host about moving to PHP 8.3 or newer. Back up first and try it on a staging copy, checking checkout, payments, shipping and tax before you touch the live shop.
WordPress news
Gutenberg 24.1 brings design tools to almost every block
Gutenberg 24.1 is mostly about consistency.2 Background images, borders, shadows and colour controls now reach almost every core block, and text shadows get their own panel in Global Styles. The Cover and Media & Text blocks also let you pick their image from the sidebar, as the Image block already does. That only matters if you run the Gutenberg plugin. Everyone else gets it in WordPress 7.2 in December.
For developers
The Presence API feature plugin is up to 0.14.0, and post locks now live in its own table.3
Around the community
Cloudflare's EmDash reaches 1.0
Cloudflare's EmDash CMS hit 1.0 on 28 September.4 It's free, open source and widely billed as a WordPress alternative, and its big idea is security. Every plugin runs in its own sandbox and can't touch your content, users or files unless you approve it, which is the opposite of how WordPress plugins work. Developers also sign each plugin release they publish.
It runs on Cloudflare or on an ordinary Node.js server, and it's built on Astro rather than WordPress, so your plugins and themes don't come with you. For most small business sites I wouldn't switch. But the plugin model is a fair criticism, and judging by the weekly vulnerability counts below, WordPress could learn from it.
WooCommerce
WooCommerce 11.2 is due next week
WooCommerce 11.2 is due the week of 6 October,5 and a second beta came out on 28 September.6 I covered what's in it last week. It includes a database update, so back up before you update, and try it on staging first if you've customised your cart or checkout.
For developers
The experimental Dual API, which turns PHP classes into GraphQL endpoints, moves out of WooCommerce core in 11.2 and becomes a separate plugin. Its proof-of-concept product and coupon endpoints are gone for good.7
Plugin security updates
I haven't seen reports of new attacks this week, but there's a long list of fixes. If you use any of these, update:8
| Plugin | Sites | What's wrong | Fixed in | Action |
|---|---|---|---|---|
| UpdraftPlus | 4M+ | After a migration, any logged-in user could read some backup storage passwords | 1.26.8 | Update |
| All in One SEO | 2M+ | Anyone could make your site run shortcodes it shouldn't | 5.0.2.1 | Update |
| OMGF | 300,000+ | Anyone could knock your site offline | 6.3.11 | Update |
| PDF Invoices & Packing Slips for WooCommerce | 300,000+ | A guest order could hide harmful code for an admin to open | 5.16.2 | Update |
| Ultimate Member | 200,000+ | Anyone could see member profile fields you'd set to private | 2.14.0 | Update |
| LatePoint | 100,000+ | Anyone making a booking could make your site run shortcodes | 5.7.1 | Update |
| Ultra Addons for Contact Form 7 | 60,000+ | Anyone could upload files that run code, if the PDF Generator is on | After 3.5.50 | Update now |
| Featured Image from URL | 60,000+ | An admin clicking a crafted link could create a new admin account | 6.0.8 | Update |
| Simply Schedule Appointments | 50,000+ | Anyone could read customers' contact details and delete appointments | 1.6.12.33 | Update |
| Simple Membership | 40,000+ | Anyone could redirect a new member's activation email, password included | 4.8.4 | Update |
UpdraftPlus was disclosed on 25 September, the day before last week's issue, and slipped through. It only leaks anything on sites moved with its migration tool where the follow-up notice was ignored, but it's on more than 4 million sites, so update anyway.9 The Contact Form 7 add-on is the one to do first if you've switched on its PDF Generator.
Ninja Forms (3.15.5) and Customer Reviews for WooCommerce (5.123.0) needed another security update after last week's. Ad Inserter (2.8.19, also from 25 September), Cache Enabler (1.8.17) and User Frontend (4.3.12) fixed serious bugs that only bite in certain setups. EWWW Image Optimizer (8.8.0) and Loco Translate (2.8.9), both on a million or more sites, fixed smaller ones. If you're not sure how to handle any of this, see my guide to dealing with a plugin security vulnerability.
The self-healing malware has a name
Last week I mentioned malware that hides from your dashboard. Sucuri has written up what looks like the same family, which it calls SC.10 It keeps copies of itself in at least eight places, including a .user.ini file, two of WordPress's drop-in files, your theme's functions.php and the database, and each copy can rebuild the others. Delete the files and the next page load puts them back. On shops it also skims card details at checkout.
The copies have to be removed in a particular order, so a quick plugin scan won't shift it. If you think you've got it, start with my hacked site guide, and if you run a shop, talk to your payment provider.
For the long tail, Wordfence's report for 21 to 27 September counted 319 new vulnerabilities across 222 plugins.11
What I'd do this week
- Still not on WordPress 7.1.2? Do that before anything else.
- Shop on PHP 7.4 or 8.0? Talk to your host about PHP 8.3 now, and test the change on a staging copy first.
- Update UpdraftPlus, All in One SEO and Ultimate Member, plus anything else in the table you use.
- Using Ultra Addons for Contact Form 7 with its PDF Generator? Update it today.
- Back up before WooCommerce 11.2 arrives next week. If an update does break something, here's how to fix a site after a bad update.
New Requirement for WooCommerce 11.6: PHP 8.1+, WooCommerce Developer Blog, 29 September 2026. ↩
What's new in Gutenberg 24.1? (30 September), Make WordPress Core, 30 September 2026. ↩
Presence API: What's new, Make WordPress Core, 2 October 2026. ↩
EmDash 1.0: the stable CMS with a secure plugin registry, Cloudflare, 28 September 2026. ↩
WooCommerce 11.2.0 Pre-release notes, WooCommerce Developer Blog, 21 September 2026. ↩
WooCommerce 11.2.0-beta.2, WooCommerce on GitHub, 28 September 2026. ↩
The Experimental WooCommerce Dual API is now a plugin, WooCommerce Developer Blog, 28 September 2026. ↩
Wordfence Intelligence vulnerability database, Wordfence, and WPScan for UpdraftPlus, All in One SEO, OMGF and Featured Image from URL. Fixed versions checked against each plugin's changelog. ↩
UpdraftPlus 1.23.8 to 1.26.7: Subscriber+ Remote Storage Credential Disclosure via Migration Notice, WPScan, 25 September 2026. Fix confirmed in the plugin's changelog on WordPress.org. ↩
SC WordPress Malware: A Self-Healing Mesh of Loaders, Drop-Ins, and a Blockchain-Controlled Backdoor, Sucuri, 30 September 2026. ↩
Wordfence Intelligence Weekly WordPress Vulnerability Report, 21 to 27 September 2026, Wordfence, 1 October 2026. ↩