CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Protect The Shire solves one problem, but risks making another worse

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6277

As cited

Copy frozen at (site build).

vulnerabilities

Protect The Shire solves one problem, but risks making another worse

WordPress.org's Protect The Shire policy, launched June 5, 2026, introduced a review hold before new plugin and theme releases are served through the update mechanism: roughly 24 hours initially, reduced to 6 hours starting July 16. The policy effectively contained one supply-chain attack (CVE-2026-18072 in Advanced Responsive Video Embedder), but delays the distribution of patches for disclosed vulnerabilities across 79 plugins with approximately 9.9 million combined installs, with no expedited clearance for critical fixes.

Why it matters: Plugin developers and site owners face a 6-hour window during which disclosed vulnerability patches remain unavailable through WordPress.org's update-check application programming interface (API), while agencies and hosting providers using automated update tools built atop that API experience the same blind spot across their entire customer base; practitioners managing at-scale deployments should verify whether their update tooling can bypass this delay.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Protect The Shire solves one problem, but risks making another worse

WordPress.org's Protect The Shire policy, launched June 5, 2026, introduced a review hold before new plugin and theme releases are served through the update mechanism: roughly 24 hours initially, reduced to 6 hours starting July 16. The policy effectively contained one supply-chain attack (CVE-2026-18072 in Advanced Responsive Video Embedder), but delays the distribution of patches for disclosed vulnerabilities across 79 plugins with approximately 9.9 million combined installs, with no expedited clearance for critical fixes.

Why it matters: Plugin developers and site owners face a 6-hour window during which disclosed vulnerability patches remain unavailable through WordPress.org's update-check application programming interface (API), while agencies and hosting providers using automated update tools built atop that API experience the same blind spot across their entire customer base; practitioners managing at-scale deployments should verify whether their update tooling can bypass this delay.

VendorsMicrosoftWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary