Skip to content
WordPress Implements AI Security Review to Prevent Malicious Plugin Updates

WordPress Implements AI Security Review to Prevent Malicious Plugin Updates

First seen 10 Sep 2026, 22:48 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 11, 2026 at 01:17 UTC
  • WordPress now uses AI to review plugin updates for security risks.
  • A backdoor incident on July 28 prompted the introduction of this automated review.
  • Plugins with high-risk scores are automatically blocked from distribution.

WordPress has introduced an automated security review system for plugin releases to enhance security before updates reach users. This decision follows an incident on July 28, where a backdoor was found in a plugin update affecting around 20,000 installations. The automated review assigns a security score to each release during a six-hour cooldown period, blocking those deemed high-risk. The system utilizes multiple AI models and Jetpack Scan to analyze changes and reduce false positives. If a release is blocked, authors are notified via email and must address the issues before resubmitting. The new process aims to prevent similar incidents in the future by ensuring that potentially harmful updates do not reach millions of sites. The automated review is part of ongoing efforts to refine security measures in the WordPress ecosystem.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-03-04
CVE-2026-20079 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-05
Cooldown period for plugin releases introduced
A six-hour cooldown period was implemented for all plugin and theme releases before distribution through the update API.
make.wordpress.org
2026-07-28
Backdoor detected in plugin update
A backdoor was found in a plugin update affecting approximately 20,000 installations, leading to immediate action by the Plugins Team.
Helpnetsecurity
2026-07-29
CVE-2026-20316 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-09
Automated security review launched
WordPress announced the launch of an automated security review system for plugin releases to enhance security.
make.wordpress.org

More articles in this cluster (3)

Following this threat?

Track CVE-2026-20079 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed