logo

WordPress Uses AI to Stop Malicious Plugin Updates Before They Reach Millions of Websites

ID: 45dd31ff-049c-5195-b878-217bf947cd13

STIX ID: report--45dd31ff-049c-5195-b878-217bf947cd13

Feed Name: cybersecurityNews.com

Threat Score
50/100

Date Published: 2026-09-10

Date Updated: 2026-09-11

Author: Guru Baran

...
...

WordPress implemented an automated, AI-driven security review and mandatory six-hour cooldown for every plugin/theme release after a malicious backdoor commit was pushed to a plugin with ~20,000 active installs; the AI review flagged the update with a high security score and the update was not distributed. The change embeds multiple AI models alongside Jetpack Scan to compute a security score and automatically block high-risk releases, notifying committers and encouraging fixes or appeals to the Plugins Team to reduce supply-chain exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.