To understand the problem with WPA3, you have to understand 3 things:

  1. WPA3 was born because the KRACK attack was able to break WPA2 in 90 seconds and will no doubt enjoy the same attention from potential attackers.
  2. WPA2 was released nearly 16 years ago and did not become widespread until about 10 years later – mainly due to costs involved. So, it is reasonably safe to assume that WPA3 will take a while to be adopted for the same reasons.
  3. WPA3 will have to be reverse-compatible with WPA2 devices, otherwise no one will adopt it apart from maybe greenfield sites. This exposes the WPA3 devices to being forced to downgrade to WPA2 and thus are vulnerable once more.

WPA3 is indeed more secure than WPA2 and as we understand it, WPA3 routers will accept connections from older (WPA2) devices, and WPA3 devices will be able to connect to older routers.

Does this mean that there is still a window of opportunity for would be attackers to compromise the connections? … sadly yes.