What happened WordPress released security update 7.0.3 on August 6 to patch 12 vulnerabilities, including a pre-auth XSS flaw on the login screen that an AI model discovered in 10 hours for $25 and attackers weaponized within 90 minutes of the patch becoming public.
Why it matters to hosts If you host WordPress sites, you need to understand that your customers' sites are now actively targeted the moment a patch drops—the window between disclosure and exploitation has collapsed to hours, not days. This isn't a cPanel problem; it's a coordination problem between patch release and customer adoption.
What to do Audit which of your WordPress installs are still running versions below 7.0.3, then contact customers to schedule updates immediately—don't wait for them to notice.
My view The real story here isn't that WordPress has security flaws; every platform does. The story is that the exploit timeline has become impossibly compressed for small operators to manage manually. A host that doesn't have automated patching in place for WordPress is now running a ticking clock on every customer site.
Does your hosting stack offer one-click or automatic WordPress core patching, and if so, are your customers actually using it?
Released 7.0.3 security update fixing 12 vulnerabilities, including a pre-auth XSS flaw exploited within 90 minutes of patch availability; also released WordPress 7.1 RC1 with accessibility changes that may break some plugins.
Announced cPanel AI, a suite of AI capabilities including Meridian (redesign) and other tools bundled for resale under hosting provider brands.
Crossed 4 million domains under management with 750,000 total customers, representing 67% customer base growth in recent period.
Authorized 7.65GW natural gas power plant in Texas for new AI data center, permitted to emit 33 million tons of CO₂ annually.
Shipped version 6.0 with rebuilt admin interface, AI ticket autopilot, and native MRR analytics.
WordPress 7.0.3 shipped a critical pre-auth XSS flaw that attackers weaponized 90 minutes after patch release. The exploit window has collapsed—your customer update workflow needs to be automated, not manual.
cPanel launched cPanel AI, embedding AI automation into its core platform and allowing hosts to resell the tools under their own brands. Control panels are now competing on automation capabilities, not just management interfaces.
Porkbun's customer base jumped 67% as it crossed 4 million domains, signaling consolidation velocity in registrars. Independents are competing on customer experience, not just price.
Amazon secured permits for a dedicated 7.65GW natural gas plant in Texas to supply a new AI data center, licensed for 33 million tons of annual CO₂. Infrastructure power requirements are reshaping feasibility and regulatory burden for hyperscaler expansions.
CVE-2026-58048 affects all supported cPanel versions and enables database privilege escalation. A critical flaw across the entire installed base requires urgent patching.
WordPress 7.0.3 patches 12 vulnerabilities including a login-screen XSS rated as the most critical. Immediate installation is recommended for all sites.
Official WordPress release announcement for 7.0.3 security update. Core team recommends immediate installation across all sites.
WooCommerce Social Login contains an unauthenticated vulnerability enabling full site takeover. Any host with ecommerce customers using this plugin needs to flag affected sites immediately.
N-able's initial patch for an N-central authentication bypass was incomplete; attackers exploited the same vector again. Incomplete patches compound customer risk and require secondary validation.
Hostinger enabled Patchstack's Node.js vulnerability scanning by default on Business and Cloud plans, surfacing 10,000 at-risk sites in weeks. Embedded vulnerability scanning is becoming a baseline hosting feature.
Hostinger placed its largest server order ever (3,000+ machines) due to extreme RAM shortages and pricing, securing a full year of capacity. Memory supply constraints are forcing hosts to overcommit capital years in advance.
Key industry deadlines between August 2026 and January 2027 will move hosting margins; calendar and compliance dates are published. Plan technical and business responses to known deadline events.
CoreWeave announced Indonesia expansion as part of its APAC push, signaling AI infrastructure demand is driving geographic diversification beyond traditional US hubs. Regional infrastructure is becoming critical for serving local AI adoption.
Virginia now requires data center operators to fully fund their dedicated electrical infrastructure, shifting cost from ratepayers to facilities. States are shifting infrastructure cost risk from grid operators to data center developers.
Grid queues and power constraints are forcing data center developers away from traditional hubs to new regions with available capacity. Site selection is now power-constrained rather than latency-optimized.
Multi-gigawatt data center campus developments are becoming the norm as AI and cloud demand reshape economics. Single buildings are no longer sufficient for hyperscaler expansion; campus strategies are the new baseline.
Hyperscalers report $600B+ capex spending yet still cannot build capacity fast enough to meet AI demand. Capital availability is not the constraint; grid and supply chain constraints are.
Texas initiated a statewide audit and moratorium on 1,800 data center applications, citing power demands 5x historical peaks. Regulatory bottlenecks are now competing with physical infrastructure as site-selection constraints.
Texas PUCT and ERCOT ordered comprehensive audit of pending data center interconnection requests. Regulatory scrutiny is intensifying around large-load interconnections driven by AI infrastructure demand.
Samsung advanced floating data center engineering as an alternative to land-based constraints. Non-traditional siting (offshore, floating) is becoming part of the infrastructure solution set as power and real estate limit onshore expansion.
Monthly roundup of data center announcements and construction updates. Track this as a leading indicator of where hyperscalers are sinking capital and which regions remain capacity-constrained.
Former Intel CEO Pat Gelsinger argues GPU-centric AI infrastructure is inefficient; power efficiency and infrastructure economics matter more than chip count. Hardware vendors are shifting focus from raw performance to power efficiency and thermal management.
HestiaCP released a security update; details not provided but indicates active maintenance of the alternative control panel. Track HestiaCP releases if you run open-source alternatives to commercial panels.
Zone, an Estonian host and registrar since 1999, joined Your.Online's roll-up, which has now completed 60+ acquisitions. Consolidation through roll-up vehicles is accelerating; independents are weighing exit versus standalone growth.
WordPress 7.1 RC1 is available for testing; stable release expected within weeks. Hosts should test 7.1 compatibility with their infrastructure and customer plugins now.
Blesta 6.0 shipped with a redesigned admin UI, AI-driven ticket automation, and native MRR reporting. Self-hosted billing platforms are now competing on automation parity with SaaS alternatives.
WordPress 7.1 includes accessibility improvements that may break plugins modifying admin screens. Test plugin compatibility before releasing 7.1 to production customers.
Samsung unveiled zHBM, zNAND-O, and BV-NAND memory technologies targeting AI data center workloads. Hardware vendors are innovating around AI infrastructure bottlenecks, signaling where capacity constraints lie.
Porkbun reached 4 million domains and 750,000 customers, representing aggressive customer growth. The registrar's strategy of customer experience and retention is working at scale.
Wholesale Internet outage reported; extent and duration not specified in summary. Monitor status pages for providers dependent on Wholesale Internet peering.