code pic

The Week in WP – 07.11.25

And now for something completely different…

It’s Friday, and time to recap what I found newsworthy in the world of WordPress. Let’s lead off with the latest headline of importance regarding a plugin security issue.

This one was reported by Patchstack hours ago (as of this writing) and involves the popular Gravity Forms plugin. Patchstack is calling this a supply chain attack. Two of the possible functions the malicious code might be able to perform on a compromised site are to create or delete users, including admins.

Gravity Forms has released a patched version and posted about the incident on their blog. It appears to only affect plugins that were manually downloaded or installed via Composer.

If you are interested in exploring other vulnerabilities in the WordPress ecosystem, there are several sources who report their findings on a regular basis:

As a related aside, WordPress will be officially dropping security support/updates for versions 4.1 – 4.6
If you are still running these versions on your website, or are not sure – Chat me up now!

Maintenance + Support

Monthly Subscription Plans

$49

/Month

University students seeking to fulfill internship requirements to graduate may now have a possible roadmap through the WordPress Foundation. According to the official release, participants can meet requirements by contributing to the open-source project, while learning valuable real-world skills.

Open to students from all fields of study, the program blends structured onboarding with a personalized contribution project. Activities are adapted to each student’s degree program and familiarity with WordPress, aiming to develop transferable skills, academic-related competencies, and active participation in the WordPress community.

  • An introduction to open source principles and the WordPress Foundation
  • Getting familiar with community tools (Slack, Make blogs, Learn platform, GitHub)
  • Setting up a personal WordPress site and publishing content

Visit the official announcement for more information.

It’s not new news, but it is coming up soon.
August 26-29 are the dates for WordCampUS in Portland, OR this year.

click the image or go to https://us.wordcamp.org/2025/ for more info.

As of today, there are still tickets available.

I found two of the most recent podcasts on WPTavern to be worth the time.


Podcast# 176 features Héctor de Prada on the power of local WordPress Meetups in building community.

https://wptavern.com/podcast/176-hector-de-prada-on-the-power-of-local-wordpress-meetups-in-community-building

Podcast #175 has Jennifer Schumacher dishing up her experiences and lessons learned from making mistakes in running her WordPress based agency

https://wptavern.com/podcast/175-jennifer-schumacher-on-learning-from-agency-mistakes

Have a great weekend!