More and more plugin vulnerabilities are coming to light, and due to AI the timeframe between a fix being released and vulnerabilities being exploited is getting shorter. In light of this, we're introducing a new policy where plugins with a vulnerability score over a certain threshold will get automatically deactivated until a patch becomes available. Once the fix is in place, the plugin will be reactivated.
Each vulnerability gets scored between 0 and 10 (called a CVSS Score). For now we're setting the threshold at 8.0. If a score is this or higher, it will be automatically deactivated. We may adjust or reevaluate this threshold over time. By choosing 8, we're hoping to target vulnerabilities that can be exploited with zero authentication (guests) or a very low level of authentication (like a "Subscriber" role).
What this means for you: if an impacted plugin does get deactivated, you may lose some features on your site until the plugin is reactivated again. This isn't ideal but we feel it's better than the alternative, which is leaving site open to hackers to exploit.
Martes, Septiembre 1, 2026
