Back to Archive

AI starts finding the vulnerabilities

For weeks the AI story in WordPress has been about a growing attack surface. This week it flipped. Wordfence's Argus, an AI research agent, uncovered a critical remote-code-execution chain in the Avada theme, which has around a million sales, and an authentication bypass in a 350,000-install plugin, work its own team describes as beyond what human researchers could manage alone.

Elsewhere, core floated a proposal to finally give WordPress first-class secret storage, and a caching-plugin failure on 7.1 turned into a wider conversation about testing against betas. Here is the week.


Beginner

WordPress backs open-weight AI in a policy letter

WordPress has signed an open letter urging US policymakers not to restrict open-weight AI models, the kind anyone can download, inspect, and run. A notable stance from a project that powers a large share of the web, and a signal of where its leadership sees AI heading.

Your host is part of your credibility

Most credibility advice stops at content, but slow, flaky hosting undercuts the trust that good content earns. Kinsta makes the case that where you host is a visible part of how professional your site feels.

What a theme builder is for

If you have ever built a homepage happily and then hit a wall on the blog and archive templates, this explains why. A clear primer on what theme builders solve and when you need one.

Developer

An AI agent found a critical RCE in Avada

Wordfence's Argus agent chained six steps into unauthenticated remote code execution in Avada, a theme with roughly a million sales. Update Avada now, and note who found it: not a person, but an AI built to outpace human researchers.

Wordfence says its AI has passed human researchers

The team behind Argus describes findings so intricate they had to ask the agent to explain its own work back to them. Whatever you make of the framing, AI-driven vulnerability discovery is now a permanent part of the WordPress security landscape.

A proposal to give WordPress real secret storage

WordPress still has no first-class way to store an API key, so plugins drop credentials into the options table in plain text. This 7.2 proposal outlines a Secrets API with WP-CLI support to close a gap that has caused credential leaks for years.

Unauthenticated RCE in GiveWP

A PHP object injection flaw lets an attacker with no account run commands on any GiveWP site that has a published donation form and an active gateway. Anyone collecting donations through GiveWP should treat this as urgent.

Business

The WP Rocket outage and a lesson about betas

After 7.1 shipped, some WP Rocket sites hit fatal errors from a bug that had been reported back in July during alpha. Jetpack uses the episode to argue that performance plugins need to test against betas like everyone else, a fair point wrapped in a little rivalry.

What AI search optimization takes in 2026

AI Overviews are cutting clicks, but pages that get cited win bigger than they used to. Themeisle pairs real data with practical steps for getting your WordPress content quoted by AI search.

Get out of the WordPress bubble

CMS Conf organizer Maciek Palmowski makes the case for WordPress people learning from other CMS communities rather than only their own. A useful nudge if your reading list has narrowed to a single ecosystem.

Non-WordPress

Inside GitHub's fastest-growing project ever

OpenClaw became the fastest-growing project in GitHub's history, and its maintainers share what six months of that felt like. A candid look at scaling an open-source project, and its security, under a firehose of attention.

Cloudflare aims to break bot-attack economics

Cloudflare's new Adaptive Intelligence engine learns from live traffic to raise the cost of running bot attacks, instead of relying on static rules attackers route around. Relevant to anyone tired of playing whack-a-mole with scrapers and abuse.

Two alleged supply-chain hackers arrested

Australian authorities arrested two men tied to TeamPCP, a group blamed for one of the longest software supply-chain attack sprees on record. A rare piece of good news in a summer thick with breaches.