Skip to main content

Studio
Scrapbook

August 2026

July has been a mix of the planned and the unplanned. A serious WordPress vulnerability landed on a Friday afternoon and had the Dev team moving fast. The rest of the month ran more to schedule. A new site went live for The Inner Temple, six months of work with West Country Water and Environment came together in their Regional Plan Document, and we sat down with Dixon Jones to talk entity maps. Add a hike up Pen y Fan and a trip to Denver for Ian and Dan, it’s been a full month. Here’s what we’ve been up to.

Bringing WCWE's Regional Plan Document to life

For the past six months, Fanatic has been working with West Country Water and Environment (WCWE) to bring its Regional Plan Document (RPD) to life. This long-term strategic document sets out how water supply and demand will be balanced across the South West. It brings together the needs of multiple sectors, while forecasting future demand and proposing sustainable solutions to improve drought resilience and protect the environment.

Following the development of the WCWE brand, we worked closely with the team to create a future-proof design system for reports, maps and data visualisations. Designed to improve clarity, consistency and accessibility, the system makes complex information easier to navigate and understand. Built to scale, it works just as effectively for comprehensive documents spanning hundreds of pages, such as the RPD, as it does for shorter, public-facing publications.

Responding to a WordPress core vulnerability

Some unplanned work for the Dev team this month. On Friday 17 July, security researchers at Searchlight Cyber published details of a vulnerability in WordPress core, nicknamed wp2shell. It’s what’s known as a pre-authentication remote code execution flaw, which is about as serious as web vulnerabilities get. “Remote code execution” means an attacker can run their own code on the server, and “pre-authentication” means they don’t need to log in first. There are no other conditions either: no particular plugin, no unusual configuration, just a stock WordPress install and a single anonymous request. That’s enough to take over a site.

Versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1 are affected. Anything on 6.8.5 or below isn’t.
Searchlight held back the technical details of how the exploit works to give site owners time to patch, which was a fair signal that everyone needed to move quickly.

The permanent fix is a core update, to 7.0.2 or to 6.9.5 for anyone on the 6.9 branch. Alongside that, our first move was to roll out a mitigation across the sites we look after, closing off the route the exploit depends on so nothing was left exposed while updates were worked through. Fortunately we were also assisted by Cloudflare and our WordPress Security Plugin of choice, who both pushed their own mitigations as soon as the vulnerability was disclosed which covered a large part of our website estate right out of the gates.

Keeping an eye on disclosures like this, and being able to act on them across a whole estate of sites in a matter of hours, is a large part of what our ongoing maintenance and hosting work covers. It’s easy to look at this and think that WordPress is somehow less secure or more vulnerable than other Content Management Systems, but that’s not the case. As WordPress is the most popular CMS in the world it gets the most attention by both malicious actors and security researchers, and staying on top of your sites updates and security means you get the full benefit of all that testing.

What we're keeping an eye on: Google and the DMA

Two things happened in Brussels this month. Neither changes anything for anyone this quarter, but both are worth following.

On 16 July the European Commission spelled out how Google has to meet obligations it’s already signed up to under the Digital Markets Act. Android needs to open up, so rival AI assistants can be summoned by voice and act inside apps the way Gemini already does. And Google has to start sharing anonymised search data (rankings, queries, clicks, views) with competing search engines at a fair price (Ars Technica has a good rundown of Google’s objections). The bit worth circling: AI chatbots that do search count as eligible recipients. Data sharing kicks in from January 2027, the Android side from July.

That’s the interesting one. A big reason nobody competes with Google is that nobody else has click data at that scale. If Perplexity and ChatGPT can buy their way in, the quality gap starts to narrow.

Then on 23 July, separately, the Commission fined Google €890 million over self-preferencing in Search and for making it awkward for Play developers to point people at cheaper checkouts. Google has 60 days to sort both out, and reckons that means pulling some Search features for European users. If you’ve got EU-facing sites, keep half an eye on that one. Results pages over there could look noticeably different come autumn.

None of it lands on UK sites directly. The CMA does its own thing here and hasn’t gone anywhere near as far. We’ll keep watching both.

Out of office

See what the team has been up to this month in their free time