WordPress has announced it’s launching an automated security review for every release of a plugin before it’s distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved.
“New plugins are reviewed before they enter the directory, but updates ship continuously after that,” David Perez, WordPress Official Plugin Repository Team Co-Lead, said. “A plugin can be secure today and introduce a vulnerability, or malicious code, in a future release.”
WordPress said the lack of a “consistent review step” between the commit of a release and the release of a plugin to downstream users meant that it could open the door for malicious attacks.
The content management system (CMS) platform noted that its automated review detected a backdoor committed to a release of a plugin with about 20,000 active installations on July 28, 2026. Because the release was within a cooldown window, the compromised version of the plugin never ended up getting distributed through the WordPress.org update API.
The plugin was closed for downloads 26 minutes after the Plugins Team was alerted to the update by WordPress security company Wordfence. WordPress did not disclose the name of the plugin.


Leave a Reply