As cited
Copy frozen at (site build).
vulnerabilities
Protect The Shire solves one problem, but risks making another worse
WordPress.org's Protect The Shire policy, launched June 5, 2026, introduced a review hold before new plugin and theme releases are served through the update mechanism: roughly 24 hours initially, reduced to 6 hours starting July 16. The policy effectively contained one supply-chain attack (CVE-2026-18072 in Advanced Responsive Video Embedder), but delays the distribution of patches for disclosed vulnerabilities across 79 plugins with approximately 9.9 million combined installs, with no expedited clearance for critical fixes.
Why it matters: Plugin developers and site owners face a 6-hour window during which disclosed vulnerability patches remain unavailable through WordPress.org's update-check application programming interface (API), while agencies and hosting providers using automated update tools built atop that API experience the same blind spot across their entire customer base; practitioners managing at-scale deployments should verify whether their update tooling can bypass this delay.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Protect The Shire solves one problem, but risks making another worse
WordPress.org's Protect The Shire policy, launched June 5, 2026, introduced a review hold before new plugin and theme releases are served through the update mechanism: roughly 24 hours initially, reduced to 6 hours starting July 16. The policy effectively contained one supply-chain attack (CVE-2026-18072 in Advanced Responsive Video Embedder), but delays the distribution of patches for disclosed vulnerabilities across 79 plugins with approximately 9.9 million combined installs, with no expedited clearance for critical fixes.
Why it matters: Plugin developers and site owners face a 6-hour window during which disclosed vulnerability patches remain unavailable through WordPress.org's update-check application programming interface (API), while agencies and hosting providers using automated update tools built atop that API experience the same blind spot across their entire customer base; practitioners managing at-scale deployments should verify whether their update tooling can bypass this delay.
- Source published
- First seen by Cybersecurity Tracker