
MCP Server for the WordPress Trac
transcript
show notes
If you want to contribute to WordPress using AI, you can now connect to the Trac MCP server to find tickets, changesets, and everything you need to dig through the backlog of pending work.
Remember that you can listen this program from:




Program transcript
Hello, I’m Alicia Ireland, and you’re listening to WPpodcast, bringing the weekly news from the WordPress Community.
In this episode, you’ll find the information from September 21 to 26, 2026.
Fourth security release of the series in barely a month and a half, and this time with critical severity: WordPress 7.1.2 fixes a responsibly reported vulnerability that allows an unauthenticated attacker to cause page template resolution to include an arbitrary local PHP file, as long as it is readable, located outside the active theme’s directories. If certain preconditions are met both in the server environment and in the active theme, this can lead to remote code execution. It has its own CVE, CVE-2026-87902.
Update recommended immediately, no excuses this time: the patches have already been backported to all branches with security support, from 4.7 to 7.0, so it’s time to check your version and update as soon as possible.
Direct consequence of the episode we already covered about the launch of WordPress 7.1 on the WordCamp US stage: Anne McCarthy announces that WordPress is abandoning the live on-stage launch format. After two rounds of the experiment, such as State of the Word 2025 and 7.1 itself at WordCamp US, the team acknowledges that tying the launch to a physical event brings more problems than advantages: complex logistics, limits on how many people from the release squad can travel to the event, and the squad itself reporting that running a process that wasn’t designed to be done on a stage adds real, extra stress.
The alternative, proposed by Matt after discussing it with Anne, is to move to a livestreamed Zoom webinar format, with no fixed event date: those who are part of the release squad and of the release itself can share the live session, while everyone else watches and asks questions, allowing more people from the team to participate depending on their time zone, without the cost of traveling to an event. This new format is already kicking off with WordPress 7.2, scheduled for early December, with more details on how to join as the date approaches.
Gutenberg has completed the migration of its JavaScript unit and integration tests, leaving Jest behind in favor of Vitest. The reason comes down to two significant advantages: better native support for modern JavaScript modules, which under Jest required maintaining special configuration every time a dependency adopted that format; and the ability to run component tests in a real browser instead of simulating one, to check things like computed styles, sizes, scroll, or keyboard interaction without relying on imitations. The Vitest tests themselves finished faster than the slowest group of the ones running on Node, so the new browser coverage hasn’t lengthened total run time.
For those who contribute to WordPress core, there is now a public and free MCP server for querying Trac from any AI assistant, with no account or API key needed. It works with Claude, ChatGPT, or any other MCP-compatible client, and allows asking things like what’s still pending on a specific ticket and which pull requests are still open, or requesting a summary of a changeset and its diff, with specific tools for searching tickets, reading a ticket along with its discussion and attachments, checking a changeset, or reviewing the timeline. By default it connects to the Core Trac, but it works the same way with the rest of WordPress.org’s Tracs, such as Meta, Themes, Plugins, bbPress, BuddyPress, or GlotPress, by changing the endpoint.
The WordPress Contributor Toolkit reaches 1.2 with a significant new feature: full support for contributing to Gutenberg as well, not just to core. The flow is parallel to that of Core: when creating a site, you choose whether to contribute to WordPress Core or to Gutenberg, a decision that can no longer be changed afterward and that determines which repository it clones and how it builds it. For Gutenberg, instead of linking a Trac ticket you link a GitHub issue, which brings with it its own pull requests with an “Apply…” button to test them directly, and once the work is done you can open the pull request in the corresponding repository without leaving the application, with device flow authentication that lives only in memory while the application is open.
WordPress Playground’s Dev Tools Dock adds one more tool: an email panel that captures and displays the emails the site generates, without setting up a mail server or checking a real inbox. When WordPress sends a message through its usual path, PHP writes it out to a sendmail-compatible program, and Playground intercepts that message in the browser instead of actually delivering it, displaying it with its subject, sender, recipient, and body, with an HTML preview if the message carries one. It’s useful for almost any plugin that sends emails through WordPress’s normal path: contact forms, welcome or approval messages in memberships, order or booking confirmations, or simply to compare how an email template looks across different themes or WordPress versions.
Third bbPress release in just over a month, though this time without any security surprises: 2.6.18 is a maintenance release focused on legacy forum imports and on password updates at first login. Users imported from legacy forum formats can now update their password when logging in for the first time, even in cases where the original forum database no longer exists; it also fixes topic statuses, reply counts, and forum dates when importing from PHPWind, and restores the Super Moderator edit link on frontend user screens.
The Community team gives updates on the migration of WordPress meetup groups from Meetup.com to events.WordPress.org, the GatherPress-based alternative. After the call for testing at the end of August, which left plenty of useful feedback, the plan for the roughly 700 affected groups is moving forward in three phases: right now work is being done on that feedback; the next step is for real groups to organize real events on the platform to see what works and what breaks, including testing the migration tool that imports data from Meetup.com; and only once the platform and that migration path have held up under real use will it open up to the rest of the groups.
Several things have already been decided: the migration tool will import upcoming events and venues as drafts for the organizer to review before publishing, but it will not copy the member list, since each person will have to join on their own with a WordPress.org account, and for now it will be run by someone from the team itself rather than the group organizer, with past events left out of this first round. Precisely for that reason, the team insists that whoever organizes a group should already start encouraging their members to create a WordPress.org account, because it is going to be an unavoidable requirement to remain in the group after the migration.
Two relevant open questions remain: whether it will be possible to migrate members in bulk by matching Meetup accounts with WordPress.org accounts, something that depends on a pending decision about user data management; and what will ultimately happen to each group’s Meetup.com page, which during the pilot will remain active but redirecting to the new platform instead of running its own parallel attendance list.
Mary Hubbard, Executive Director of the WordPress Project, takes on the presidency of the Open Website Alliance, the body that brings together the organizations behind Drupal, Joomla!, TYPO3, and WordPress to jointly defend free software. The position is rotational among the Alliance’s members, so it’s now WordPress’s turn.
The Alliance was born in 2024 out of the joint work of these four projects in response to the European Union’s Cyber Resilience Act, arguing before lawmakers that their content management systems are not just basic digital infrastructure, but the machinery through which real businesses reach their customers and sell products, and that any security requirement should take that economic role into account without stifling how the communities of developers, translators, and collaborators who maintain the software work.
Hubbard frames the appointment along the same lines as WordPress’s recent signing of the letter on open-weight AI models: the idea that everyone should have the freedom to use, modify, and share the tools they depend on.
And finally, this podcast is distributed under a Creative Commons license as a derivative version of the podcast in Spanish; you can find all the links for more information, and the podcast in other languages, at WPpodcast .org.
Thanks for listening, and until the next episode!