bbioonThemes
  • Home
  • Blog

Category: Bug Fixing

Bug Fixing, Core Updates

What WooCommerce 10.6.1 actually fixes

The Add to Cart with Options block compared hyphenated slugs against labels with spaces, so variable product selections failed validation. WooCommerce 10.6.1 fixes that, reorders new payment gateways, and drops the stray number from single shipment labels.

Read Article
Bug Fixing, Core Updates

WordPress 6.9.4 fixes what 6.9.2 and 6.9.3 missed

WordPress 6.9.4 re-applies three security fixes that 6.9.2 and 6.9.3 left incomplete: PclZip path traversal, XXE in getID3, and a Notes authorization bypass. It also covers the WP-CLI commands I use to update core and check the files afterwards.

Read Article
AI, Bug Fixing, Development

Neuro-symbolic fraud detection with differentiable rules

Weighted BCE starves when fraud is 0.2% of your data. I walk through adding a differentiable rule loss in PyTorch, what it does to ROC-AUC, and why both models need thresholds tuned the same way.

Read Article
Bug Fixing, Core Updates, Development

WordPress 6.9.3 and the stringable object regression

WordPress 6.9.3 is a fast-follow fix for a 6.9.2 regression that blanked out sites whose themes returned stringable objects to template_include. Here is what broke, and what you need to update.

Read Article
Bug Fixing, Core Updates

WordPress 6.9.2 patches ten vulnerabilities, so update now

WordPress 6.9.2 landed on March 11, 2026 with fixes for ten vulnerabilities, among them blind SSRF, a PoP chain in the HTML API and an XXE in getID3. What each one lets an attacker do, and how to ship the update with WP-CLI.

Read Article
Bug Fixing, Core Updates

WordPress performance: fixing the fetchpriority logic

Core was tagging hidden Gutenberg images as high priority and hurting LCP. Ticket #64823 fixes that, and Performance Lab is dropping Web Worker Offloading after 6,000 updates with no feedback.

Read Article
Bug Fixing, Design, Development, Front-end

Scalable z-index values without magic numbers

Magic numbers like z-index: 99999 are guesses. How I set up z-index tokens in CSS variables, pair a modal with its backdrop using calc(), and use isolation to keep a component’s layering inside the component.

Read Article
Bug Fixing, Development

WordPress security: the risk is your plugins, not core

Almost every WordPress vulnerability comes from a plugin or theme, not from core. Where the risk actually sits, the hardening I put on sites I manage, and the maintenance habits that keep them clean.

Read Article
Bug Fixing, Core Updates

WooCommerce Store API vulnerability: how to check and patch

CVE-2026-3589 is a CSRF flaw in the WooCommerce Store API, affecting versions 5.4 to 10.5.2, that can be used to create admin accounts through batch requests. How the flaw works, and how to check your own version with WP-CLI or a small PHP snippet.

Read Article
Bug Fixing, Core Updates, Development

WooCommerce 10.5.3 patches a critical Store API bug

WooCommerce 10.5.3 patches a path validation bug in the Store API batch endpoint that let attackers skip nonce checks and gain admin access via CSRF. Don’t roll back to 10.5.2; update now and test your checkout.

Read Article

Posts navigation

Previous 1 2 3 4 … 17 Next

bbioonThemes

Senior WordPress Engineer
Toptal & Codeable Expert

Connect

  • GitHub
  • Twitter
  • LinkedIn
  • Codeable

Explore

  • Expertise
  • Work
  • Insights
  • Blog

Resources

  • bbioonThemes
  • Contact
  • Privacy Policy
© 2026 bbioonThemes. All rights reserved.
Privacy