Kimb Jones

Founder at Make Do. We help teams stabilise, improve and support complex WordPress websites and connected systems

  • About me
  • Projects & Work
  • Portfolio
  • WordPress services
  • Events & speaking
  • Contact me

We’ve got WordPress. We’ve got hosting. We’ve got a plugin for that. We’re fine!

October 2, 2026 by Kimb Jones Leave a Comment

Sometimes the title of this post is true. Often it is a stack of thrown together parts with nobody responsible for the complete full working service.

An AI-discovered security release is not a suggestion

WordPress 7.1.1 landed with 17 core bug fixes, editor fixes, and 11 security fixes. WordPress told people to update ASAP. (WordPress 7.1.1 announcement)

There are people in our industry who still treat “update immediately” as “optional”, because the last time someone updated something, a lead gen form broke on a Friday afternoon.

Leaving a security release just sitting there because you have no staging, no recovery point and no idea who owns the plugins is how things get broken quickly.

Also, blindly and automatically applying every update with no checks or tests on the journeys that actually make money is how you create a different kind of problem.

Hosts like Pantheon treated 7.1.1 as a major security event, because this is a new breed of AI-discovered issues that can’t be ignored, they need action immediately (Pantheon release note) and although managed WordPress hosts generally have these things handled there are going to be millions of sites out there left with these gaping holes in them.

How about some physical AWS damage?

Regardless of your stack when AWS messes up, you’ll probably notice. This happened back in mid-September when AWS messed up and was unable to restore access to cloud infrastructure! This wasn’t some intern fudging a command though, this was real physical damage in Bahrain and UAE directly related to the ongoing regional conflict. Pretty serious stuff.

Multiple AWS zones were affected and data that customers had not moved was in some cases way beyond recovery options. (Reuters)

This is obviously an extreme case. Most clients are not planning for armed conflict to mess up their recovery plans.

The recent Automattic drama is not a platform crisis

Remember when Automattic’s board put Matt Mullenweg on leave, appointed an interim CEO, then reinstated him a few days later. That followed the existing row with WP Engine. It is a real governance story. It is not, by itself, a reason to rip out an independently hosted WordPress site. (TechCrunch on the leave, TechCrunch on his return)

Clients mix up WordPress the software, WordPress.org, WordPress.com, and Automattic the company so open source and data ownership still matter but only if the project was built so you actually control the code. WordPress still wins in this situation, in fact, it proves it’s worth every time Matt and the Automattic board try to make it look bad!

That is the work I am interested in at Make Do. Not a rebuild for the sake of it. Ownership of the full platform and security for the service we provide.

Filed Under: General

AI is finding WordPress vulnerabilities faster but don’t panic (yet)

September 30, 2026 by Kimb Jones Leave a Comment

AI is finding WordPress vulnerabilities faster. The core team has more work. If you run WordPress, get on 7.x.x.x.x.x (scream).

Don’t panic, this is a good thing, sort of. Let’s see what I mean.

What actually shipped in the recent slew of AI-discovered WordPress releases?

WordPress 7.1.2 was another major security release. The core team said it loud, update ASAP and automatic background updates will do their job where they are enabled. (WordPress 7.1.2 announcement).

This is what happened for 99% of our clients on our managed systems. The 1% that had sites to large, custom or complex to have the updates pushed out automatically had them lined up and ready to go within 24 hours.

So what happened? Well, Robert Ressl was thanked for disclosing that an unauthenticated attacker could, under certain conditions, make page template do some wild things like include readable PHP outside the active theme directories.

So if both the server and the active theme meet these conditions, that can lead to remote code execution.

See the full info here: WordPress.org news, GitHub advisory.

Scary but manageable

My opinion is that this is not a “WordPress is finished” story. It is a “core had a nasty hole in templates and they patched it quickly and effectively.”

The fix was also (as ususal) backported down to 4.7 but the team still recommends that only the most recent version is actively supported in the official 7.1.2 announcement.

So if you are sitting on an old version of WordPress because “it still works,” you now have more to worry about.

Singapore’s Cyber Security Agency has also warned that versions before 7.1.2 are exposed and that a proof of concept is public and that they consider the issue actively exploited. So everyone needs to treat that as a reason to patch, not a reason to go hunting. (CSA Singapore).

Seriously, upgrade ASAP.

Whatabout AI vibepentesting?

The version of this story plastered all over LinkedIn and X is that AI is chewing through WordPress core code and spitting out contributors (and attackers) more bugs.

Some of that is true in a boring way. The AI models are excellent at reading large PHP stack and spotting things that humans would likely never find. But this is a positive, not a negative.

However, I will not do is credit this purely to AI unless the team behind it confirms it was done without human intervention. The WordPress team who reported this credited Robert Ressl and his own write-up presents a HUMAN disclosure via HackerOne, then a public post after the fix.

AI-assisted review will obviously increase the volume of “this looks wrong” findings in core, plugins and custom themes. That is extra work for maintainers. It is also extra noise. A lot of vibe-generated discovery will be wrong, incomplete, or only dangerous on a lab stack that looks nothing like WordPress in real life on your host.

The bit I actually care about

If AI-assisted contributors and researches are going to keep pressure on WordPress, plugins and custom code, the honest outcome becomes simply that “we use AI to secure your site.”

That’s it. We treat WordPress as a system that gets probed, looked at, tested, updated, and recovered. Nothing has changed and all of this just makes the final product more secure and stable in the long run.

Vibepentesting is real but it does not just mean “paste the theme into a chat and hope it finds a problem” because if you try that with any old theme it will likely find some real issues and also a pile of nonsense. It will also generate “findings” that nobody would reproduce on the live stack. It needs a lot more human expertise on top of this right now to really matter.

Think of it as “experienced people using better search over a large codebase, then proving the issue properly and disclosing it in a more frequent and informed way.”

I am not going to say that WordPress is doomed because LLMs can read PHP. Plenty of platforms will get the same treatment. The sites that cope are the ones where someone already had a security path, a recovery point, and permission to use them.

Oh and update your site!

Filed Under: General

Next Page »
Kimb Logo

I run Make Do WordPress agency, a technical agency helping teams build, stabilise, improve and support complex WordPress websites, web applications and connected digital platforms.

  • Email
  • LinkedIn

Built by Kimb Jones and powered by WordPress. Jump to top of page.