CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution

September 14, 2026

WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution Ravie LakshmananSep 14, 2026Web Security / Vulnerability WordPress has announced it's launching an automated security review for every release of a plugin before it's distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved. "New plugins are reviewed before they enter the directory, but updates ship continuously after that," David Perez, WordPress Official Plugin Repository Team Co-Lead, said. "A plugin can be secure today and introduce a vulnerability, or malicious code, in a future release." WordPress said the lack of a "consistent review step" between the commit of a release and the release of a plugin to…