WordPress 7.1, available since August 19th, arrived after an unusually busy few months for core security and ships with all of those fixes in place, alongside a number of accessibility improvements. 7.2 is scheduled for December.
WordPress 7.1 – What’s New
The editor has now finally caught up in terms of responsive styling: Block appearance can now be set per screen size directly in the editor. For Greyd.Suite users this is nothing new, as Greyd had already provided that functionality. Same goes for interactive states (hover, focus, active) and configurable breakpoints.
There are also some changes with regards to media handling. In Chrome and Edge, WordPress can now resize images directly in the browser before upload instead of on the server — less data over the wire, less work for your server. Firefox and Safari fall back to the familiar server-side path automatically, so uploads work either way. There’s also new support for AVIF, HEIC and HDR gain-map images.
WordPress 7.1 also comes with two new blocks: Tabs and Playlist (groups audio tracks into one player). The table of contents block, initially planned for the release, was moved to 7.2.
While not all planned collaboration features have been shipped, more and more features in that regard are now available, e.g. notes can now be attached to specific text inside blocks and @mentions trigger email notifications linking straight to the conversation in the editor.
Interesting changes for developers: The SVG icon API standardizes the way custom icons are registered and rendered. The Abilities API has been expanded with filtering, execution lifecycle hooks, unified public exposure flag and client-compatible JSON schema. DataViews, DataForm and View Config continue maturing with Site Editor screens and layouts now filterable.
Important note: Please make sure to test everything in detail before rolling out 7.1 on public websites. The post editor is now always iframed including on sites registering legacy meta boxes. Any plugin reaching across the editor document boundary in JS or CSS needs checking. Also worth mentioning: Block CSS output is now more conditional, e.g. Cover block styles only output when the page actually contains a Cover block. Reported as a breaking change for sites pulling content in remotely.
Helpful Links:
Outlook: The Road to WordPress 7.2
Beta for 7.2 is expected for the end of October, with the final release currently proposed between December 8th and 10th. Nothing is fixed until the beta lands, but the work already done in the Gutenberg plugin gives a good indication of what December will bring.
The change most likely to be felt in everyday work is performance. A series of improvements to how the editor handles large content means long, block-heavy pages stop feeling sluggish. On a test post with a thousand paragraphs, selecting all blocks went from nearly 17 seconds to under half a second.
Revisions are becoming genuinely collaborative. Each version now gets its own shareable URL, so a review conversation can point directly at the change in question instead of living in email threads and screenshots. Client feedback moves to where the change actually is.
For agencies, 7.2 brings more curation control. You will be able to hand a site over with a locked-down design system without breaking the design and without taking content editing away from your client. A new filter also shows which blocks carry custom design overrides, which helps when auditing an inherited site or preparing a handover.
On the design side, labels become styleable, duotone palettes can be edited directly in Global Styles, lists gain new alignment options, the Query Loop gains block gap, and groups get new spacing options. The table of contents block postponed from 7.1 is expected here as well.
A Word on Security
WordPress has seen a noticeable increase in security activity in recent months. July brought a critical core patch for an unauthenticated exploit chain that was being exploited within hours of disclosure, followed by two further security releases in August. All of these fixes are included in 7.1.
Core, however, is not where most of the risk sits. The large majority of vulnerabilities reported across the WordPress ecosystem are found in third-party plugins and themes rather than in core itself, and that volume has been growing. AI is clearly a factor in the acceleration, though it cuts both ways: attackers use it to find and combine vulnerabilities faster, while several of this summer’s core issues were found and responsibly disclosed by AI-assisted research teams before anyone could exploit them. The pace has picked up on both sides.
What does this mean for website owners and agencies?
The fundamentals haven’t changed—but they’ve become even more important. Keeping WordPress, plugins, and themes up to date, using appropriate security solutions, and regularly reviewing which plugins are actually needed are important steps toward reducing risk. Solutions like Greyd.Suite replace multiple individual plugins with one integrated solution, helping to reduce the number of components that need to be maintained and, in turn, the potential attack surface.
Good security starts with a simple principle: keep your setup lean, keep it updated, and only use the components you really need.






