Web design & dev news, tracked daily.
Front-end, performance, security, and platform-tooling news relevant to building and maintaining ecommerce sites.
What changed, as it happens.
Tracked daily from primary sources. The items below are what we're watching for clients right now.
WordPress patches a login-screen flaw that needs no account to reach
WordPress 7.0.3 fixes twelve vulnerabilities, including stored XSS in several blocks, server-side request forgery, privilege escalation on multisite networks and information disclosure. The most severe is a cross-site scripting issue on the login screen, scored 8.9 and reachable without authentication; WordPress's security repository states it can be escalated to remote code execution under conditions outside the attacker's control, requiring successful social engineering of the target and explicit interaction from them. Fixes are backported to WordPress 4.7 and later, and sites with automatic updates enabled are receiving them. Researchers from Anthropic, pwn_ai and Aikido Security were among those credited.Source: Search Engine Journal →
Our take: Minor releases install themselves on most WordPress sites and this one backports to 4.7, so the patch is probably already on. Most owners have not checked. Auto-updates get switched off during a migration or a plugin conflict and rarely get switched back on, and an 8.9 on the login screen with no account required is a bad one to find out you missed. The escalation path needs the victim to click, a condition that holds until someone builds a convincing enough page.
Read our full take →WordPress 7.1 rewrites the admin list tables, and some plugins will notice
WordPress 7.1, scheduled for release on 19 August 2026, changes the HTML structure of admin post list tables to fix an accessibility bug that has been open for eleven years. Screen readers currently announce each row using the checkbox column header, "Select All", rather than the post title. In 7.1 the checkbox column moves from a th to a td, the post-title column becomes a th with scope="row" and carries an aria-label holding the post title, and collapsed cells in the responsive view move to a flex layout. Search Engine Journal reports the code at risk is plugins using CSS or JavaScript selectors that target specific th or td elements in those tables, and that public-facing site functionality should be unaffected.Source: Search Engine Journal →
Our take: This one sorts itself by stack. A BigCommerce or Shopify storefront has no WordPress admin to break, and where WordPress runs the blog the damage is confined to a screen customers never see. Eleven years is a long time for a screen reader to have been reading "Select All" in place of every post title.
Read our full take →A forged Apple login token takes over any WordPress site running WooCommerce Social Login
CVE-2026-8457 is a critical authentication-bypass vulnerability in the WooCommerce Social Login plugin, affecting versions up to and including 2.8.7 and fixed in 2.8.8. It scores 9.8 out of 10 on CVSS. The plugin's Apple login handler does not validate Apple's JWT identity tokens against Apple's public keys, so an attacker can forge a token carrying any email address and be signed in as the matching user. Wordfence describes the result as unauthenticated attackers being able to log in as any existing WordPress user, including administrators. Administrator accounts carry no exclusion protection here, so a successful attempt hands over full control of the site without any legitimate credentials.Source: Search Engine Journal →
Our take: Update to 2.8.8 today if this plugin is installed anywhere you touch. A 9.8 with a forged-token path and no credentials required is the class that gets scanned for within days of disclosure, and social login is the kind of plugin switched on once during a launch and never opened again. For most BigCommerce and Shopify merchants the exposure sits on the WordPress blog or landing-page install on a subdomain beside the store, where the plugin list has not been read in a year and an administrator account is one forged token away.
Read our full take →CSS border-shape takes shaped elements past what border-radius can do
CSS-Tricks published an explainer on border-shape, a CSS Borders Module Level 4 property that accepts the same values as clip-path — including the newer shape() function — but shapes the whole element rather than clipping it. That distinction is the point: borders, box-shadows, and outlines follow the shaped path instead of being cut off at it, which makes putting a real border on a non-rectangular CSS shape straightforward for the first time. Support is Chrome-only as of July 2026, so treat it as something to explore rather than ship.Source: CSS-Tricks →
Our take: Chrome-only means explore, don't ship. For stores it's eventual relief from the SVG-mask gymnastics behind badge shapes and promo callouts, a progressive-enhancement candidate for late 2026, not a today tool.
Read our full take →NN/G floats a “UX.md” — machine-readable context for AI-generated design
Nielsen Norman Group argues UX work should shift toward curating machine-readable context that AI tools consume when they generate design, rather than producing human-only deliverables like personas and reports. The anchor is real: Google Labs open-sourced DESIGN.md in April 2026, a file that lives alongside a product’s code and pairs machine-readable values — colors, type sizes, spacing — with human-readable guidance so a tool knows what a color is actually for. “UX.md” itself is NN/G’s thought experiment, not a standard anyone implements yet. Worth reading as a direction, not a checklist.Source: Nielsen Norman Group →
Our take: The direction is real even if UX.md isn't a standard yet: machine-readable design context is how AI-generated pages stay on-brand. We keep exactly that, tokens plus intent, in this site's repo; it's why AI-assisted edits don't drift the palette.
Read our full take →
Custom ecommerce software, AI apps, and SEO — the work other agencies quote around, built in-house.
20+ years of BigCommerce engineering, now AI-augmented. Tell us your store, your stack, and your deadline — we quote fixed scope on the first call.