Fixed: in the Security tab the API key field and the key-in-URL showed the word full instead of the key (a variable was reused by the new access level picker). The stored key was never changed; it displays correctly again. If you copied the key from 2.11.0, copy it again.
No focus outline is left on icon buttons after a mouse click
Access levels for connected apps: Read only, Read and edit, or Full access, chosen when you approve an app (Read and edit is preselected) and changeable any time in Connected apps
Apps are only offered the tools their level allows; refused calls say which level is needed; undoing a change needs the level that could have made it
The API key has its own level in the Security tab
Existing connections and the API key stay at Full access until you change them
New Works with section on the Connect tab: Gutenberg, Elementor 3 and 4, Divi 4 and 5, content, caches and settings, showing what is active on the site
Health checks moved to the System tab; optional items such as Elementor, Divi and page caches show as information, not warnings
The blue focus ring WordPress adds after clicking a button or link is gone; keyboard focus keeps a coral outline
Block editor (Gutenberg) tools: read blocks as an outline or one block at a time, and write block markup with replace, append, prepend, insert and replace-block modes; markup is validated before saving
Divi 4 tools: read and write shortcode layouts section by section with nesting checks; Divi 5 sites are pointed at the block tools
Clear caches from the assistant: object cache, transients, Elementor, Divi and eleven page cache plugins
Read and change common site settings, validated together and rollback-able
Activate or deactivate plugins and switch themes (off until you turn on Allow activation)
wp_ping and wp_get_content now say which editor built each page and which cache plugins are installed
Cleaner typography: the admin screen now uses the Inter typeface, bundled with the plugin (no external font requests), with regular, medium, semibold and bold weights used consistently
New History tab: every change made through WP MCP is recorded (which app, what changed, when) and can be rolled back from the admin screen
Rollback restores only what the change touched: content fields, custom fields, terms, featured image and Elementor layouts; created items are trashed; deleted items come back (permanent deletes keep the same ID); uploads and terms are removed; file edits restore their pre-edit snapshot
If an item was edited after the change, rollback asks before overwriting those edits
AI apps can use the new wp_list_history and wp_rollback tools
Fixed: backslashes in post content and custom fields were removed when saving through WP MCP
After clicking Connect with Claude, the WP MCP page watches for the connection to finish, tries to close the Claude tab it opened, and reloads with a connected notice and an updated Connected apps list
New connect screen: choose Claude, ChatGPT, Claude Code, Cursor, VS Code or another app and follow one-click steps (copy URL and open, ready-made command, Add to Cursor / Add to VS Code links)
Connected apps list with a Revoke button that cuts access immediately
Setting to turn OAuth sign-in on or off; the API key now lives under Advanced
Consent page recognizes Cursor and VS Code return addresses