CVE Tools
Back to feed
Research web-app info-disclosure

The WordPress update button isn’t telling the truth anymore

Patchstack·By Lana Rafaela··7 min read
CVE Tools coverage

New research reveals that the recent changes to WordPress.org’s update process—designed to improve security—have introduced a critical lag between when patches are made available and when they appear in user dashboards. Despite reducing the delay from 24 to 6 hours, this gap still allows attackers to exploit publicly disclosed vulnerabilities before site owners are notified of an update. The issue affects over 9.9 million installations across 79 plugins, including high-severity fixes rated up to CVSS 10.0. Hosting companies and agencies using automated tools face similar limitations due to reliance on the same delayed API. Patchstack now offers free 30-day protection for hosting partners to close this window immediately.

What WordPress.org’s 24-hour update delay actually cost the ecosystem, and why 6 hours isn’t better.

If your WordPress dashboard says a plugin is up to date, you believe it. Or, you used to. 

That was the practical effect of Protect The Shire, WordPress.org’s initiative to lock down roughly 78,000 plugins and themes living in the WordPress.org directory. It was rolled out on June 5th, 2026, with a mandatory 24-hour hold before releases reached sites.…

Continue reading on Patchstack