WordPress 7.2 is scheduled for final release on December 9, 2026, with Beta 1 targeted for October 20–22 and Release Candidate 1 for November 17–19. Matt Mullenweg is leading the release, and the roadmap was published September 18, 2026 on Make WordPress Core by Anne McCarthy, who led the 7.1 release. If you run a WordPress site, this one matters more than most: the headline features are security changes that will touch how you log in and how plugins handle your passwords and API keys.
One honest caveat before anything else. The roadmap describes every feature as something being “pursued, not promised.” Some items on this list could miss the final release. That’s normal for WordPress development, but it means you should treat the timeline and features below as the plan, not a guarantee.
When WordPress 7.2 Is Coming Out
WordPress runs on a predictable three-releases-a-year cycle, and 7.2 is the third major release of 2026. Here’s where things stand:
- Beta 1: October 20–22, 2026
- Release Candidate 1: November 17–19, 2026
- Final release: early December, proposed date December 9, 2026, with a livestream launch
If that schedule holds, the update lands in your dashboard roughly three months from now. The security features are worth understanding in advance — one of them will change what you see when you do administrative tasks.
“Sudo Mode”: WordPress Will Ask for Your Password Again
The most noticeable change for site owners is being called “sudo mode,” and it’s deliberately modeled on how banks and financial apps behave. Before you perform certain sensitive actions in wp-admin — think changing a user role, adjusting security settings, or anything that could do real damage — WordPress will ask you to type your password again to re-confirm it’s really you.
Why does this matter? Right now, if you step away from your desk and leave your WordPress session open, anyone who sits down has full admin access. Sudo mode requires fresh proof of identity at the moment it counts, not just when you first logged in.
The feature is still at an early-work stage, so expect it to evolve through the beta period. Paired with it is a hardening pass on Application Passwords — the credentials external tools use to connect to your site without your real password — which should make them safer to use.
The Secrets API: Plugins Finally Get a Safe Place for Passwords
This one is mostly under the hood, but its effect on your site’s safety is real. WordPress 7.2 introduces a Secrets API — the first built-in, supported way for plugins to store credentials like API keys and tokens.
Today, plugins that need a secret usually stash it in the options table in plain text, where it can be seen by anyone with database access and sometimes exposed through the options editor or the REST API. The new API gives developers three functions — wp_set_secret, wp_get_secret, and wp_delete_secret — to store secrets encrypted at rest using libsodium. These secrets stay hidden from the options.php admin page and the REST settings endpoint.
Two things site owners should know about this: it does not come with an admin interface in 7.2 — you’ll never click anything to manage these secrets — and the real payoff comes over time. As plugin developers adopt the API, your stored API keys get meaningfully harder to steal.
What’s New in the Block Editor
The editor gets a solid round of refinements rather than anything dramatic:
Notes gets suggestion mode
The Notes feature — WordPress’s in-editor collaboration tool — is gaining a suggestion mode. Instead of editing someone’s content directly, you can propose changes as notes that the author accepts or rejects. Emoji reactions and a toolbar shortcut are coming to Notes as well, making it quicker to react to a teammate’s draft without typing a full comment.
If you work with an editor, a VA, or guest authors, this is the single most useful editor change in 7.2.
Two new blocks: Description List and Table of Contents
The Description List block is a semantic HTML element for term-and-definition content — glossaries, product spec lists, FAQs — done properly instead of faked with paragraphs or tables, which helps accessibility and search engines read your page structure.
The Table of Contents block is the bigger deal. A stable, built-in TOC block has been requested for years, and 7.2 is finally delivering one. If you publish long how-to guides, this will replace the plugin or theme feature you’ve been using.
Global Styles can now style form elements
Global Styles in the Site Editor will be able to style buttons, text inputs, and select dropdowns without custom CSS. Until now, making your contact form’s button match your theme required code or a plugin. After 7.2, it’s a styling panel.
Dashicons are out, SVG icons are in
The admin and menu bar are swapping the old Dashicons font icons for SVG icons — slightly sharper visually, with better behavior for screen readers and Windows High Contrast mode.
Meet Ipsum, the New Default Theme
Every year, WordPress ships a new default theme named for the year. 7.2 breaks that tradition: the new default theme is called Ipsum, a minimal blank-canvas blog theme, and it signals a new direction where default themes get proper names instead of year labels.
Ipsum is deliberately simple: a clean starting point for personal blogs that stays out of your way. Your current theme keeps working — Ipsum simply becomes the default on fresh installs.
What’s Deliberately Not in 7.2
The roadmap is as interesting for what it leaves out. Real-time collaborative editing — the “two people editing one post at the same time, Google Docs-style” feature — is off the table for the third consecutive release. The team isn’t saying no forever, but they’re clearly not rushing it.
AI features are also staying out of core. All of WordPress’s AI work — including the MCP adapter and WebMCP experiments — lives in the separate WordPress AI plugin. If you want AI-assisted writing or AI-powered site tools, that’s where to look, not in 7.2 itself.
Should You Test the Beta? A Blogger’s Honest Guide
When Beta 1 lands in late October, every WordPress news site will tell you to try it. Here’s the practical version:
Testing the beta on your live site: don’t. Betas can and do break things — that’s their job. A broken beta on your production blog means lost visitors and lost income.
Testing on a staging site: worth it, if you’re comfortable with staging. Sudo mode and the new blocks could interact with your theme or plugins in ways worth discovering early. The official path is straightforward: make a full backup, spin up a staging copy with your host, install the WordPress Beta Tester plugin from Plugins → Add New, set it to track the bleeding-edge trunk or the beta release stream, and update. Then click through your most important pages, your forms, and your publishing workflow.
If you just want the benefits: wait. Beta testing is for the curious and the plugin developers. Most bloggers should let the release candidates ship, let plugin authors catch up, and update in mid-to-late December when the dust has settled. The security features will still be there.
One prerequisite matters more than anything else: be on a current, patched version before you test anything. WordPress 7.1.2 shipped September 22, 2026 with a fix for a critical flaw, CVE-2026-87902 — if you’re running anything older, patching that comes first, well before thinking about betas. (See our earlier coverage of that critical WordPress flaw for why patching promptly matters.)
While you’re preparing, confirm your site has a valid SSL certificate — the password re-checks in sudo mode assume HTTPS — and that your host offers one-click staging. If it doesn’t, that’s a reason to reconsider your host, not to test on production.
The Bottom Line for Site Owners
WordPress 7.2 is a quieter kind of release: no flashy AI, no real-time collaboration, no dramatic redesign. Instead, it does the unglamorous work that actually protects your business — password re-checks before dangerous actions, encrypted storage for plugin secrets, and hardened application passwords. The editor additions (suggestion-mode Notes, a real Table of Contents block, form styling in Global Styles) are the kind of improvements you notice the week after updating.
Mark December 9 on your calendar. Back up before you update. And remember the roadmap’s own warning: these features are being pursued, not promised — watch the beta announcements to see which ones survive to the final release.
Sources: the WordPress 7.2 roadmap published on Make WordPress Core, and wp-content.co’s breakdown of the 7.2 roadmap.
Frequently Asked Questions
When is the WordPress 7.2 release date?
The final release is targeted for December 9, 2026, with a livestream launch. Beta 1 is expected October 20–22, 2026 and Release Candidate 1 on November 17–19, 2026. These are targets, not guarantees — the roadmap notes that features and dates are pursued, not promised.
What is sudo mode in WordPress 7.2?
Sudo mode means WordPress will ask you to re-enter your password before sensitive actions in wp-admin — similar to how a bank re-authenticates you before a transfer. It’s designed to protect you if you leave an admin session open on a shared computer or if a session cookie gets stolen.
Will WordPress 7.2 include AI features or real-time collaboration?
No to both. Real-time collaborative editing was deliberately left out for the third consecutive release, and AI features remain in the separate WordPress AI plugin (which includes an MCP adapter and WebMCP experiments) rather than in core.
What is the WordPress 7.2 Secrets API?
It’s a new developer-facing API that lets plugins store credentials like API keys encrypted at rest using libsodium, via the wp_set_secret, wp_get_secret, and wp_delete_secret functions. Secrets stay hidden from the options.php admin page and the REST settings endpoint. There’s no admin UI for it in 7.2 — it works silently in the background to make your stored secrets harder to steal.
Is WordPress 7.2 safe to install right away?
Major releases are generally safe, but the smart move is to wait a few weeks after the December release while plugin authors update their code. Always back up before updating. If you want to test earlier, use the WordPress Beta Tester plugin on a staging copy of your site — never on your live blog.
What is the new default theme in WordPress 7.2?
Ipsum — a minimal, blank-canvas blog theme. It’s the first default theme not named for its year, signaling a new naming direction for default themes. You don’t have to switch if you like your current theme; it simply becomes the default on fresh installs.
