Home Blog

Open Channels FM: Invisible Unicode Attacks, CrowdSec Source Leak, and the AI Coding Boom Explored

0

Invisible characters challenge spam filters, CrowdSec deals with a code leak, and AI is shifting what matters in software development.

bbPress: bbPress 2.6.18 is out!

0

bbPress 2.6.18 is a maintenance release focused on forum imports and first-login password upgrades.

Imported users can now upgrade their passwords on first login for more legacy forum formats, including cases where the original forum database is no longer available. This release also corrects PHPWind topic statuses, reply counts, and forum dates during import, and restores Super Moderator edit links on front-end bbPress user screens.

bbPress 2.6.18 requires PHP 7.2 or newer and WordPress 6.0 or newer. Sites running an older PHP version should update PHP before upgrading bbPress. Read the 2.6.18 upgrade notes for importer compatibility details.

These changes are also in the 2.7 development branch. The Plugin Directory’s development trunk remains at 2.7.0-alpha-3.

Download bbPress 2.6.18 from WordPress.org, or update from your WordPress dashboard.

WordPress.org blog: WordPress Takes Its Turn Leading the Open Website Alliance

0

I’m happy to announce that I am now serving as president of the Open Website Alliance (OWA), representing the WordPress Foundation. The Alliance brings together the community organizations behind Drupal, Joomla!, TYPO3, and WordPress to advocate for open source and share practices that benefit their projects. I represent the WordPress Foundation in this role, which rotates among the Alliance’s members.

WordPress announced its participation in the Alliance in 2024, building on our work with Drupal, Joomla!, and TYPO3 to respond to the European Union’s Cyber Resilience Act. While many open source projects focus on underlying digital infrastructure, our content management systems power the websites where businesses reach customers and sell products and services. We asked policymakers to account for that economic role when setting security requirements, while respecting how communities of developers, translators, educators, and other contributors build and maintain the software. We share a belief that everyone should have the freedom to use, change, and share the tools they rely on.

This commitment to openness builds on efforts such WordPress’s recent signing of the Open Weights and American AI Leadership letter. Our mission to democratize publishing means giving anyone a voice and welcoming everyone to contribute. Working with other communities puts those values into practice beyond WordPress, supporting the freedoms that make participation possible. I invite you to read the Open Website Alliance charter to learn more about the commitments its members share and how the Alliance works.

OpenStation Blog: Drag, Drop, Preview: How a Post Gets Written in OpenStation

0

I started writing a post (this post!).

Then, as usually happens, I needed a picture, so I dragged one straight from my desktop into OpenStation. No downloading, no extra tabs needed, no extra spaces in the editor, no more “in which tab was the image!?”… I just dragged it from my desktop…

Happy

Done!

And then I thought the post was already descriptive enough to tell how much we enjoy creating content in OpenStation… But I missed the preview. I wanted to see what the post would look like and edit it in real time. And it happened, I just had to click on the eye icon in the title bar of this editor.

This is probably my favourite kind of productivity, the boring stuff becoming pleasantly simple…

And yes, this whole post was written while recording the video 🙂

But I thought that a quick sanity review from one of my bots would make the post nicer for SEO. So I just saved the draft, and gave it to my agent 😉

And the best part, is that EVERYTHING that my Agent did, is traceable.

Dashboard view for SEO Medic user profile in OpenStation, showing user information, total content, comments, updates, and recent activity.

Switch to OpenStation

Stripe Payment Links vs Embedded WordPress Forms: Which Should You Use?

0

Should you share a Stripe Payment Link or embed a payment form on your WordPress site? Compare setup, branding, features, and real costs.

The post Stripe Payment Links vs Embedded WordPress Forms: Which Should You Use? appeared first on Themeisle Blog.

How to Build a WooCommerce Print Shop Order Form With File Upload

0

Build a WooCommerce print-shop page where customers upload artwork, pick a size, and unlock bulk discounts. Step-by-step PPOM walkthrough inside!

The post How to Build a WooCommerce Print Shop Order Form With File Upload appeared first on Themeisle Blog.

OpenStation Blog: A better way to use WordPress

0

I have been using WordPress for a long time, and I still love it. But wp-admin has basically worked in the same way for years.

OpenStation is our attempt to change that.

It’s a simple idea: instead of moving from one admin page to another, you have a desktop where you can open different parts of WordPress at the same time.

A screenshot of the OpenStation interface displaying a welcome message and a list of recent posts on the left, with a detailed view of the 'A better way to use WordPress' post on the right.

Your WordPress. Your workspace.

You can open your posts, pages, media, plugins, WooCommerce or any OpenStation app in different windows.

You can move them around, minimize them or put two things next to each other.

It may sound like a small difference, but once you start using WordPress this way, it changes a lot.

Real-time previews

You can also see your changes while you are working on them.

No need to constantly jump between wp-admin and the frontend just to check how something looks.

Screenshot of an OpenStation interface showcasing a blog post titled 'A better way to use WordPress' with a dark theme and multiple sections discussing features and mobile compatibility.

Apps inside WordPress

This is one of my favorite parts.

We are building apps like AllTerrain Forms, Photo Editor (And more!) specifically for OpenStation.

They are still WordPress plugins, but they feel much more like normal desktop apps.

A black Nike Air Force 1 sneaker displayed on a table, featuring a blue swoosh and 'OpenStation' branding.

WordPress on your phone

We also wanted OpenStation to work properly on mobile.

You can install it as a PWA and use WordPress from your phone almost like any other app.

A digital interface displaying a grid of application icons with sections for apps and system tools, including options for dashboard, posts, media, and settings.

Performance Is Fast. Really fast.

OpenStation is not only about changing how WordPress looks.

We have put a lot of work into making it fast. In many cases, opening and moving between WordPress screens is faster than using them directly from wp-admin.

We are also working on caching and preloading parts of WordPress before you need them.

The goal is very simple: you click something and it opens FAST.

And it is still WordPress

This is important.

We are not trying to replace WordPress or build another platform on top of it.

Your plugins are still your plugins. WooCommerce is still WooCommerce. Your content stays in WordPress.

OpenStation just gives you a different way to use all of it.

And, of course, it is open source.

Thank you

And finally, a big thank you to everyone in the WordPress community who has tried OpenStation, shared feedback, reported bugs or simply told others about it.

Grid of contributors to OpenStation showcasing their profile pictures and the number of merged pull requests (PRs) each has contributed.

And especially to all the contributors who are helping us build it. OpenStation would not be what it is today without you.

There is still a lot we want to do, and seeing people contributing, experimenting and building things with OpenStation is probably the best part of the whole project.

Thank you ❤

Open Channels FM: OCN Week in Review #4

0

This week Robert Jacobi shared about the evolving landscape of open source and tech. Highlights include AI’s growing role in security, WordPress and Apache fortifying their processes, LibreOffice redefining productivity with privacy, LoopConf rethinking event funding, and Switzerland’s bold move toward digital sovereignty. Explore how accountability, control, and sustainability are shaping the future of open technology.

Open Channels FM: Drawing the Line Between Openness and Noise in the Digital World

0

Is sharing everything always good? Bob Dunn reflects on transparency and the noise in online spaces.

WordPress.org blog: WordPress 7.1.1 Maintenance and Security Release

0

This security and maintenance release features 17 bug fixes on Core, 19 bug fixes for the Block Editor, and 11 security fixes.

Because this is a security release, it is recommended that you update your sites immediately.

You can download WordPress 7.1.1 from WordPress.org, or visit your WordPress Dashboard, click “Updates”, and then click “Update Now”. If you have sites that support automatic background updates, the update process will begin automatically.

WordPress 7.1.1 is a short-cycle release. The next major release will be version 7.2 and is currently planned for December.

For more information, please visit the WordPress 7.1.1 HelpHub site.

Security updates included in this release

The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by Jakub Herman.
  • Comments, including notes, can be reparented by any authenticated user, reported by Justin Hart, Viridis Security.

Thank you to these WordPress contributors

This release was led by Adam Silverstein, Adrian Duffell, Andrei Draganescu, and Aaron Jorbin.

WordPress 7.1.1 would not have been possible without the contributions of the following people. Their asynchronous coordination to deliver maintenance and security fixes into a stable release is a testament to the power and capability of the WordPress community.

Aaron Jorbin, abrahamfariaz, Adam Silverstein, Adi Moldovan, Adrian Duffell, Aki Hamano, Alex Concha, Andrea Fercia, andreasca, Andrei Draganescu, Andrew Duthie, Andrew Serong, André Maneiro, annezazu, Anthony White, Arkaprabha Chowdhury, Ashar Fuadi, Azragh, Barry, buffer1024, Chunhui Ouyang, Courtney Robertson, Dagan, Daniel Richards, Daniel Rodriguez, Darshit Rajyaguru, David Biňovec, Deepak Kumar, Dennis Snell, DevSaiful, Dhruvang21, Dominik Schilling, Ehtisham Siddiqui, Ella Van Durpe, Erick Wambua, FahimMurshed, Fernando Tellado, fiocavallari, George Mamadashvili, George Vasiliades, gregbenz, Harish Tewari, Hit Bhalodia, Isabel Brison, Jake Spurlock, Jamie Dąbrowiecki, Jb Audras, Jeffrey Paul, Jeremy Felt, Jiwoon Kim, Joe Dolson, Joe Hoyle, Joe McGill, Joen Asmussen, Johannes Jülg, John Blackbourn, Jon Surrell, Jonathan Desrosiers, Josh, Kamran Abdul Aziz, Khokan Sardar, Kira Schroder, kleisauke, Kushagra Goyal, l1onofjudah, Lance Willett, luksusspokoju, Manzoor Wani, Marco Ciampini, marcs0h, Marin Atanasov, Michael, Mohammad Jangda, mrkenobi, Mukesh Panchal, Nawazkhan Pathan, Nik Tsekouras, Parth Jogi, Pascal Birchler, Paul Biron, Paul Kevan, Peter Wilson, Rafie Muhammad, ramonopoly, Rashed Hossain, Ressl, Riad Benguella, Rudy Faile, Sainath Poojary, Scott Kingsley Clark, Sergey Biryukov, Shail Mehta, Shameem – a11n, siliconforks, Slava Abakumov, Stephen Bernhardt, Sukhendu Sekhar Guria, Ugyen Dorji, Utsav Ladani, vortfu, Weston Ruter, w3bdsgn, wolf45 plus representatives from Automattic, Bluehost, GoDaddy, Pantheon, and WP Engine.

Backports

As a courtesy, the security fixes are being backported, where necessary, to all branches eligible to receive security fixes (currently through 4.7). As a reminder, only the most recent version of WordPress is actively supported. The backports are in progress and will ship as they become ready.

How to contribute

To get involved in WordPress core development, head over to Trac, pick a ticket, and join the conversation in the #core channel. Need help? Check out the Core Contributor Handbook.

Props to Ehtisham Siddiqui, Lance Willett, Weston Ruter, and Adam Silverstein for proofreading.