WordPress 7.0 Launch Exposes AI API Keys to Theft Risks

WordPress 7.0 Launch Exposes AI API Keys to Theft Risks

First seen 23 May 2026, 00:52 UTC LetsdatascienceTechtimes 78% similarity 64.5

Article Content

Browse articles
ThreatCluster

On May 20, 2026, WordPress released version 7.0, which introduced an AI infrastructure that inadvertently exposed API keys due to a security vulnerability in the AI integration setup form. This flaw allows browser autofill to visually reveal sensitive API keys, potentially leading to significant financial losses as these keys can be worth tens of thousands of dollars. Security experts, including Patchstack founder Oliver Sild, warned that the combination of this vulnerability and existing plugin weaknesses could result in a surge of API key theft. WordPress co-founder Matt Mullenweg defended the platform, asserting that most sites remain secure. The issue highlights the increased risks associated with AI integrations in widely used platforms like WordPress, affecting approximately 43% of websites globally. The vulnerability is distinct from server-side breaches, as it exploits client-side rendering and form handling. As of now, no patches or fixes have been announced for this specific issue.

Key Points: • WordPress 7.0 exposes AI API keys through browser autofill in the integration setup form. • The vulnerability could lead to significant financial losses, with stolen keys valued at tens of thousands of dollars. • WordPress co-founder claims most sites are secure, despite the new risks introduced by AI integrations.

ThreatCluster AI

Timeline

2025-11-05
CVE-2025-11749 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-20
WordPress 7.0 released
Version 7.0 introduced AI infrastructure but lacked real-time collaboration features.
Techtimes
2026-05-22
Security vulnerability reported
A bug in WordPress 7.0 allows API keys to be exposed via browser autofill in the setup form.
Letsdatascience
Recent
Experts warn of API key theft surge
Security experts predict a rush by hackers to exploit the vulnerability for API key theft.
Letsdatascience

Community

Browse all →