Helpnetsecurity WordPress Implements AI Security Review to Prevent Malicious Plugin Updates
Article Content
- •WordPress now uses AI to review plugin updates for security risks.
- •A backdoor incident on July 28 prompted the introduction of this automated review.
- •Plugins with high-risk scores are automatically blocked from distribution.
WordPress has introduced an automated security review system for plugin releases to enhance security before updates reach users. This decision follows an incident on July 28, where a backdoor was found in a plugin update affecting around 20,000 installations. The automated review assigns a security score to each release during a six-hour cooldown period, blocking those deemed high-risk. The system utilizes multiple AI models and Jetpack Scan to analyze changes and reduce false positives. If a release is blocked, authors are notified via email and must address the issues before resubmitting. The new process aims to prevent similar incidents in the future by ensuring that potentially harmful updates do not reach millions of sites. The automated review is part of ongoing efforts to refine security measures in the WordPress ecosystem.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-20079 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…