WordPress will now automatically review every plugin release before it reaches the WordPress.org update API, blocking any version that appears high risk. The change follows a recent backdoor incident in a plugin with about 20,000 active installations, where the compromised release was stopped before distribution. #WordPress #WordPressorg #Wordfence
Keypoints
- Every WordPress plugin release will now be reviewed before distribution.
- High-risk releases are automatically blocked from the update API.
- A recent backdoor was found in a plugin with about 20,000 active installations.
- The six-hour cooldown period lets AI models and Jetpack Scan analyze each release.
- Authors must fix blocked releases and publish a new version to proceed.
Read More: https://www.helpnetsecurity.com/2026/09/10/wordpress-automated-plugin-security-review/