logo

$20 per zero-day is already the WordPress plugin reality

ID: 17bde991-8738-5d11-89ee-7740c0323f7e

STIX ID: report--17bde991-8738-5d11-89ee-7740c0323f7e

Feed Name: Help Net Security

Threat Score
75/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Mirko Zorz

...
...

Researchers built an AI-driven scanning and verification pipeline that, in 72 hours, surfaced and manually verified 300+ critical zero-day vulnerabilities in WordPress plugins (pre-auth RCEs, SQLi, privilege escalation, SSRF, automated downgrade chains), highlighted a low per-vulnerability cost, the strain on disclosure triage, and warned that similar automated pipelines could be used by attackers to scale zero-day discovery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.