News

But that’s about to change, as Automattic today announced that those with business-tier accounts on WordPress.com can now install third-party themes and plugins built by other WordPress users.
Attackers have found a way to escalate the benign WordPress REST API flaw and use it to gain full access to a victim's server by installing a hidden backdoor.