Techtimes WordPress 7.0 Launch Exposes AI API Keys to Theft Risks
Article Content
- •WordPress 7.0 exposes AI API keys through browser autofill in the integration setup form.
- •The vulnerability could lead to significant financial losses, with stolen keys valued at tens of thousands of dollars.
- •WordPress co-founder claims most sites are secure, despite the new risks introduced by AI integrations.
On May 20, 2026, WordPress released version 7.0, which introduced an AI infrastructure that inadvertently exposed API keys due to a security vulnerability in the AI integration setup form. This flaw allows browser autofill to visually reveal sensitive API keys, potentially leading to significant financial losses as these keys can be worth tens of thousands of dollars. Security experts, including Patchstack founder Oliver Sild, warned that the combination of this vulnerability and existing plugin weaknesses could result in a surge of API key theft. WordPress co-founder Matt Mullenweg defended the platform, asserting that most sites remain secure. The issue highlights the increased risks associated with AI integrations in widely used platforms like WordPress, affecting approximately 43% of websites globally. The vulnerability is distinct from server-side breaches, as it exploits client-side rendering and form handling. As of now, no patches or fixes have been announced for this specific issue.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Anthropic and CVE-2025-11749 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…