AI Finds 300 WordPress Plugin Zero-Days
Reported by Dev.to — AI: AI found 300 WordPress plugin zero-days in 72 hours. I build plugins. Here's what changed for me.. Analysis and context written by TickrWire.
An AI scan discovered 300 zero-day vulnerabilities in WordPress plugins within 72 hours, prompting a developer to re-evaluate their plugin's security.

- An AI scan found 300 zero-day vulnerabilities in WordPress plugins within 72 hours.
- The developer's own plugin had 35 vulnerabilities before a security review.
- AI can be a powerful tool for identifying security risks in software.
- Regular security audits and the use of AI in testing can significantly improve plugin security.
A developer, who also creates WordPress plugins, utilized an AI tool to scan for security vulnerabilities. The AI discovered 300 zero-day vulnerabilities in various plugins over the course of 72 hours. This experience led the developer to reflect on their own plugin's security, which had previously been reviewed and found to have 35 vulnerabilities. The developer's plugin, a chatbot, underwent a security review before its release. The discovery of such a large number of vulnerabilities in a short time frame highlights the potential for AI in identifying security risks in software. This has significant implications for developers, as it underscores the importance of rigorous security testing and the potential benefits of leveraging AI in this process.
Developers need to be aware of the potential security risks in their plugins and utilize tools like AI scans to identify vulnerabilities.
Businesses that rely on WordPress plugins should ensure that their plugins are regularly audited for security vulnerabilities to protect their websites and data.
Investors in companies that develop WordPress plugins should consider the security implications of their investments and encourage robust security testing.
Students learning about web development and security should understand the importance of security testing and the role AI can play in this process.
The general public should be aware of the potential security risks associated with WordPress plugins and the steps being taken to mitigate these risks.
- Zero-day vulnerability
- A previously unknown security vulnerability in software that can be exploited by attackers.
AI bias estimate: The article appears to be a factual account of the developer's experience with AI security scanning, with minimal bias. (Automated estimate, not a definitive judgement.)
New White House strategy clarifies military tech priorities: undersea, outer space and AI - Breaking Defense
AI in an iron grip: How dictatorships use artificial intelligence to strengthen their rule - theins.press
Exclusive-How a Texas student blew the whistle on a rogue AI hacking attempt - The Mighty 790 KFGO
SecurityI wrote a test for prompt injection. It passed while the attack worked.
SecurityI Built an AI Code Reviewer. Then OWASP Broke It.
AI ToolsMeta AI’s new Mac app wants you to talk to your apps
Meta released a new Mac application that lets users control apps and dictate text using voice commands powered by its Muse Spark AI model.
Stripe, OpenRouter finally strike a deal - Banking Dive
Stripe and OpenRouter have partnered to integrate Stripe's payment processing with OpenRouter's AI model aggregation platform.
How one Philadelphia school is using AI to strengthen student learning, not replace teachers - CBS News
A Philadelphia school is integrating AI tools to support teachers and improve student outcomes, focusing on collaboration rather than replacement.
Student Journalists: AI Is Changing Our Work — And Not For the Better - The 74
A student journalism outlet argues that AI tools are degrading the quality and authenticity of their reporting.
Don’t mistake chatbot intelligence for consciousness - The Economist
The Economist argues that advanced chatbots lack true consciousness despite their impressive intelligence, urging caution against anthropomorphizing AI.
BusinessBinance now lets AI agents trade, but keeping them in check is largely up to users
Binance has launched Agent OS, allowing AI agents like ChatGPT and Claude Code to execute trades, though risk management remains primarily the user's responsibility.