Web Design & Dev · News

August 2026 — Web Design & Dev news.

August 2026

What changed, as it happens.

Tracked daily from primary sources. The items below are what we're watching for clients right now.

  1. WordPress · Security

    WordPress patches a login-screen flaw that needs no account to reach

    WordPress 7.0.3 fixes twelve vulnerabilities, including stored XSS in several blocks, server-side request forgery, privilege escalation on multisite networks and information disclosure. The most severe is a cross-site scripting issue on the login screen, scored 8.9 and reachable without authentication; WordPress's security repository states it can be escalated to remote code execution under conditions outside the attacker's control, requiring successful social engineering of the target and explicit interaction from them. Fixes are backported to WordPress 4.7 and later, and sites with automatic updates enabled are receiving them. Researchers from Anthropic, pwn_ai and Aikido Security were among those credited.Source: Search Engine Journal →

    Our take: Minor releases install themselves on most WordPress sites and this one backports to 4.7, so the patch is probably already on. Most owners have not checked. Auto-updates get switched off during a migration or a plugin conflict and rarely get switched back on, and an 8.9 on the login screen with no account required is a bad one to find out you missed. The escalation path needs the victim to click, a condition that holds until someone builds a convincing enough page.

    Read our full take →
  2. WordPress · Accessibility

    WordPress 7.1 rewrites the admin list tables, and some plugins will notice

    WordPress 7.1, scheduled for release on 19 August 2026, changes the HTML structure of admin post list tables to fix an accessibility bug that has been open for eleven years. Screen readers currently announce each row using the checkbox column header, "Select All", rather than the post title. In 7.1 the checkbox column moves from a th to a td, the post-title column becomes a th with scope="row" and carries an aria-label holding the post title, and collapsed cells in the responsive view move to a flex layout. Search Engine Journal reports the code at risk is plugins using CSS or JavaScript selectors that target specific th or td elements in those tables, and that public-facing site functionality should be unaffected.Source: Search Engine Journal →

    Our take: This one sorts itself by stack. A BigCommerce or Shopify storefront has no WordPress admin to break, and where WordPress runs the blog the damage is confined to a screen customers never see. Eleven years is a long time for a screen reader to have been reading "Select All" in place of every post title.

    Read our full take →
  3. WordPress · Security

    A forged Apple login token takes over any WordPress site running WooCommerce Social Login

    CVE-2026-8457 is a critical authentication-bypass vulnerability in the WooCommerce Social Login plugin, affecting versions up to and including 2.8.7 and fixed in 2.8.8. It scores 9.8 out of 10 on CVSS. The plugin's Apple login handler does not validate Apple's JWT identity tokens against Apple's public keys, so an attacker can forge a token carrying any email address and be signed in as the matching user. Wordfence describes the result as unauthenticated attackers being able to log in as any existing WordPress user, including administrators. Administrator accounts carry no exclusion protection here, so a successful attempt hands over full control of the site without any legitimate credentials.Source: Search Engine Journal →

    Our take: Update to 2.8.8 today if this plugin is installed anywhere you touch. A 9.8 with a forged-token path and no credentials required is the class that gets scanned for within days of disclosure, and social login is the kind of plugin switched on once during a launch and never opened again. For most BigCommerce and Shopify merchants the exposure sits on the WordPress blog or landing-page install on a subdomain beside the store, where the plugin list has not been read in a year and an administrator account is one forged token away.

    Read our full take →
All Web Design & Dev news

Custom ecommerce software, AI apps, and SEO — the work other agencies quote around, built in-house.

20+ years of BigCommerce engineering, now AI-augmented. Tell us your store, your stack, and your deadline — we quote fixed scope on the first call.