Kimb Jones

Founder at Make Do. We help teams stabilise, improve and support complex WordPress websites and connected systems

  • About me
  • Projects & Work
  • Portfolio
  • WordPress services
  • Events & speaking
  • Contact me

AI is finding WordPress vulnerabilities faster but don’t panic (yet)

September 30, 2026 by Kimb Jones Leave a Comment

AI is finding WordPress vulnerabilities faster. The core team has more work. If you run WordPress, get on 7.x.x.x.x.x (scream).

Don’t panic, this is a good thing, sort of. Let’s see what I mean.

What actually shipped in the recent slew of AI-discovered WordPress releases?

WordPress 7.1.2 was another major security release. The core team said it loud, update ASAP and automatic background updates will do their job where they are enabled. (WordPress 7.1.2 announcement).

This is what happened for 99% of our clients on our managed systems. The 1% that had sites to large, custom or complex to have the updates pushed out automatically had them lined up and ready to go within 24 hours.

So what happened? Well, Robert Ressl was thanked for disclosing that an unauthenticated attacker could, under certain conditions, make page template do some wild things like include readable PHP outside the active theme directories.

So if both the server and the active theme meet these conditions, that can lead to remote code execution.

See the full info here: WordPress.org news, GitHub advisory.

Scary but manageable

My opinion is that this is not a “WordPress is finished” story. It is a “core had a nasty hole in templates and they patched it quickly and effectively.”

The fix was also (as ususal) backported down to 4.7 but the team still recommends that only the most recent version is actively supported in the official 7.1.2 announcement.

So if you are sitting on an old version of WordPress because “it still works,” you now have more to worry about.

Singapore’s Cyber Security Agency has also warned that versions before 7.1.2 are exposed and that a proof of concept is public and that they consider the issue actively exploited. So everyone needs to treat that as a reason to patch, not a reason to go hunting. (CSA Singapore).

Seriously, upgrade ASAP.

Whatabout AI vibepentesting?

The version of this story plastered all over LinkedIn and X is that AI is chewing through WordPress core code and spitting out contributors (and attackers) more bugs.

Some of that is true in a boring way. The AI models are excellent at reading large PHP stack and spotting things that humans would likely never find. But this is a positive, not a negative.

However, I will not do is credit this purely to AI unless the team behind it confirms it was done without human intervention. The WordPress team who reported this credited Robert Ressl and his own write-up presents a HUMAN disclosure via HackerOne, then a public post after the fix.

AI-assisted review will obviously increase the volume of “this looks wrong” findings in core, plugins and custom themes. That is extra work for maintainers. It is also extra noise. A lot of vibe-generated discovery will be wrong, incomplete, or only dangerous on a lab stack that looks nothing like WordPress in real life on your host.

The bit I actually care about

If AI-assisted contributors and researches are going to keep pressure on WordPress, plugins and custom code, the honest outcome becomes simply that “we use AI to secure your site.”

That’s it. We treat WordPress as a system that gets probed, looked at, tested, updated, and recovered. Nothing has changed and all of this just makes the final product more secure and stable in the long run.

Vibepentesting is real but it does not just mean “paste the theme into a chat and hope it finds a problem” because if you try that with any old theme it will likely find some real issues and also a pile of nonsense. It will also generate “findings” that nobody would reproduce on the live stack. It needs a lot more human expertise on top of this right now to really matter.

Think of it as “experienced people using better search over a large codebase, then proving the issue properly and disclosing it in a more frequent and informed way.”

I am not going to say that WordPress is doomed because LLMs can read PHP. Plenty of platforms will get the same treatment. The sites that cope are the ones where someone already had a security path, a recovery point, and permission to use them.

Oh and update your site!

Filed Under: General

Recent Posts

  • AI is finding WordPress vulnerabilities faster but don’t panic (yet)
  • Updates careplans and the reality of recent AI-driven WP updates
  • Salesforce Is Complicated. The Integration Problems Are Not!
  • “We Need a Rebuild” Is Often the Last Symptom, Not the First Problem

Like what you read?

Sign up to my mailing list for occasional updates.

About Kimb Jones

I’ve been a web designer since the 90's and co-founded the Make Do WordPress agency.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Kimb Logo

I run Make Do WordPress agency, a technical agency helping teams build, stabilise, improve and support complex WordPress websites, web applications and connected digital platforms.

  • Email
  • LinkedIn

Built by Kimb Jones and powered by WordPress. Jump to top of page.