April 2025

WordPress 6.8.1 Maintenance Release

WordPress 6.8.1 released with 15 bug fixes across Core and Block Editor. It is a maintenance update, with more planned for 2025. Automatic updates will occur for eligible sites. Download from WordPress.org or via the Dashboard. Special thanks to contributors, especially Aaron Jorbin, for making this release possible. To contribute, visit Trac and join relevant Slack channels.

https://wordpress.org/news/2025/04/wordpress-6-8-1-maintenance-release/

How to Duplicate a Page in WordPress (3 Easy Methods)

TLDR: Duplicate pages in WordPress for efficiency, design consistency, and A/B testing. Methods include using plugins (e.g., Jetpack, Yoast Duplicate Post, Duplicate Page), manual duplication, or custom code for advanced users. Essential tips: review duplicates, rename titles, update SEO settings, and adjust URL slugs. Improve efficiency further with Jetpack AI Assistant for content generation and editing.

https://jetpack.com/resources/how-to-duplicate-a-page-in-wordpress/

How To Clear the WordPress Cache: 5 Ways To Clear All Your Caches

Clear WordPress cache using plugins (WP Rocket, W3 Total Cache, WP Fastest Cache) and browser methods. Caching speeds up site loading by storing copies of pages, but updates may require manual cache clearing to reflect changes. Instructions for clearing caches in various plugins and browsers (Chrome, Safari, Firefox) are provided, alongside server and CDN cache clearing methods.

https://wpastra.com/guides-and-tutorials/how-to-clear-wordpress-cache/

Wordfence: The World’s Leading Quality WordPress Vulnerability Intelligence Provider

TL;DR: Wordfence 2024 Report
– Released 2024 Annual WordPress Security Report confirming Wordfence's leadership in WordPress vulnerability intelligence via high-quality research and Bug Bounty Program.
– 8,233 vulnerabilities added in 2024 (41.7% of CVEs); 4,534 in 2025 (29%).
– Processed 65.8% of vulnerabilities in software with 50,000+ installs in 2024; 68.2% in 2025.
– 45.2% of high-threat vulnerabilities addressed in 2024; 66.7% for software with 50,000+ installs.
– Other providers focus on lower-impact vulnerabilities, creating noise and poor disclosure practices.
– Wordfence prioritizes impactful vulnerabilities, maintaining free detailed intelligence for community protection and security improvements.

https://www.wordfence.com/blog/2025/04/wordfence-the-worlds-leading-quality-wordpress-vulnerability-intelligence-provider/

Interesting WordPress Malware Disguised as Legitimate Anti-Malware Plugin

Wordfence published its 2024 WordPress security report, revealing a malware variant disguised as a normal plugin (‘WP-antymalwary-bot.php'), allowing attackers to maintain site access, hide the plugin, and execute remote code. Detected on January 22, 2025, it was swiftly addressed with a malware signature and later a firewall rule for premium users. The malware can log administrators in, execute commands via REST API, and reinfect sites using modified wp-cron.php. Indicators of compromise include C&C server pings and modified theme files. This malware indicates a trend towards AI-generated threats.

https://www.wordfence.com/blog/2025/04/interesting-wordpress-malware-disguised-as-legitimate-anti-malware-plugin/

Scroll to Top