For the past decade, the number of security vulnerability reports submitted to WordPress sat around 20 – 30/month. Last month it was 450! And there were two security fixes marked ‘urgent’ in three weeks. So I’d like to explain what is happening in layman’s terms, and what a responsible WP site owner needs to do – especially when that site is the face of your business.
How Security for WordPress Has Changed
I’ve told clients for years that WordPress is a target because it’s installed on so many websites, and that the same number that makes it a target is also what gives it the largest and best developer base in the world (I may be biased). That logic hasn’t changed. But with AI there are some new risks and some better ways to manage WordPress security.
Invisible Vulnerabilities
It isn’t that the WordPress code suddenlybecame insecure. WordPress code has been tested and re-tested by thousands of contributors for two decades. The obvious mistakes have been fixed for years, and continue to get caught quickly.
What’s showing up now is a different category of flaw entirely: one that only appears when several (separately correct) pieces of code interact in a specific (non-obvious) sequence.
Finding these kinds of flaws by manual review means holding an enormous amount of context in your head and testing combinations that have no obvious reason to be tested. A human could, in theory, do this. And for many, it is their entire job to test sequences for security issues. It takes months to find anything- and most of the time leads to a dead end. The ‘flaws’ that AI is catching (July, 2026) are effectively invisible to humans.
Now, with AI, the entire codebase (thousands of ‘snippets’) of WordPress, can be held in memory, and thousands of combinations of tests can be executed in hours instead of months. That’s the reason we have 450 vulnerability submissions last month instead of the usual 30.
Note: keep in mind, a ‘submission’ is when someone thinks they’ve found a vulnerability. It is not a confirmed issue.
Patching a Vulnerability
Once one of these flaws is found, it goes one of two ways. The responsible path is that of a researcher, often AI-assisted. He/she reports it privately, the security team patches it, and only after the fix is done, does the public writeup follow. That’s what happened with 7.0.2.
The other path skips reporting entirely: someone runs the same kind of AI-assisted search with the intention of exploiting it.
7.0.2 security patch went out on a Friday; by Saturday, we saw folks exploiting it (likely with AI helping attackers reproduce the exploit from the published disclosure). The speed of that is new. And it creates more risk for WordPress site owners.
How To Keep WordPress Secure
So far, my advice is pertaining to core WordPress, but most vulnerabilities come from plugins. Your plugins and themes do not have the benefit of thousands of full-time developers- they are the biggest risk surface area. The advice about plugins and their security has not changed.
What has changed, in practice, is that the attackers are working faster, and so are the developers. In this race the protection of your site has shifted from applying updates safely to applying them quickly.
What determines whether a given site is actually safe in the age of AI is:
- how quickly the updates are applied
- the security risk surface for each plugin and theme(do the authors publish updates?)
- A firewall stopping bad actors between patch release times and patch deployment times
- plus the standard security best practices like good passwords and hosting
The sites that stay safe in the Age of AI, are the ones with someone actually paying attention continuously. It’s never been more important to take backups, install a firewall and upgrade immediately (within hours).
Need a hand? It seems like a good time to let you know we offer just such maintenance services.
New! Welcome-Email AI Agent
Looking at email marketing? Don’t forget a welcome series – folks are 4x more likely to open the first email than any other email that you send! Enter your email and we’ll send you to our custom AI Agent that will help you craft five highly converting emails in a welcome series! Then see this post for the tutorial.

Cathy Mitchell
Single Mom, Volunteer, Lifelong Learner, Jesus Follower, Founder and CEO at WPBarista.
