Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
Source Entity
Lorenzo Franceschi-Bicchierai

Critical vulnerabilities in WordPress are currently being exploited by hackers, prompting urgent calls for site administrators to update their software. Security researchers have noted that sophisticated AI models are increasingly being used to identify these high-value remote code execution flaws.
The WordPress Security Crisis: A Deep Dive into RCE Vulnerabilities
The Threat Landscape
Recent reports confirm that two critical security flaws within the WordPress ecosystem are currently being exploited in the wild. These vulnerabilities allow for remote code execution (RCE), a catastrophic failure state that permits unauthorized actors to seize control of affected web servers. With millions of websites still running susceptible versions of the software, the scale of the potential compromise is immense. Cybersecurity firms including Patchstack, Hexastrike, and WatchTowr have issued urgent warnings, noting that the window for remediation is rapidly closing as automated exploitation campaigns gain momentum.
The Role of AI in Vulnerability Research
An alarming development in this cycle is the intersection of advanced artificial intelligence and exploit development. Security researchers have begun leveraging high-end AI models, such as the referenced GPT5.6 Sol Ultra, to identify and reproduce complex exploit chains. The ability to utilize AI to bridge the gap between theoretical vulnerability and a functional proof-of-concept (PoC) for as little as $25 significantly lowers the barrier to entry for malicious actors. This shift suggests a future where the speed of vulnerability discovery outpaces the traditional manual analysis performed by defenders.
The Economics of Exploit Brokers
The market for RCE vulnerabilities has become increasingly lucrative, with brokers reportedly paying upwards of $500,000 for high-impact exploits. This financial incentive structure creates a race between security researchers, who aim to disclose flaws to facilitate patching, and exploit brokers, who seek to monetize zero-day or recently patched vulnerabilities. The case of the 'wp2shell' discovery highlights how independent researchers, such as those at Searchlight Cyber, are working to document these chains, but the sheer volume of exploit brokers creates a persistent threat to global infrastructure.
Defensive Challenges and Forced Updates
In response to the severity of these flaws, WordPress has taken the unprecedented step of enabling forced updates for vulnerable instances. While this serves as a critical safety net, it underscores the difficulty of maintaining security across a fragmented ecosystem where millions of site owners may be unaware of their current patch status. The reliance on forced updates indicates that passive notification is no longer sufficient to protect the vast, heterogeneous landscape of the modern web from automated, high-speed exploitation.
Future Trends in Web Security
Looking forward, the integration of AI into both offensive and defensive cybersecurity will define the next decade of web infrastructure management. As AI continues to solve complex mathematical and logical problems—such as the Cycle Double Cover conjecture—the capability to find 'unbreakable' code flaws will only improve. Organizations must transition toward 'security-by-default' architectures, where updates are automated and immutable, reducing the reliance on human intervention to prevent the catastrophic consequences of RCE exploits.
Conclusion
The current WordPress security situation serves as a stark reminder of the fragile state of web security. With exploit brokers incentivizing rapid development and AI tools lowering the cost of discovery, site administrators must prioritize immediate updates. The transition from manual patching to automated, forced security updates is a necessary evolution, but the underlying threat of AI-assisted exploitation remains a formidable challenge that requires constant vigilance and robust defensive innovation.
Multiple Citing Sources