Five Hours to Mass Exploitation: How AI Changed the Speed of WordPress Attacks

WordPress security used to run on a comfortable cycle: a flaw is disclosed, a patch appears, owners update eventually.

Patchstack’s State of WordPress Security in 2026 puts the median gap between disclosure of a critical flaw and mass exploitation at five hours. Eleven thousand vulnerabilities were logged in 2025, nine in ten in plugins, and nearly half had no fix on the day they went public.

The driver is automation: a patch goes into AI tooling and scanners sweep the internet hours later.

Two things still work. Auto-updates, with staging behind them. And a firewall — when a flaw ships without a patch, a WAF rule is often the only protection there is.

Share this post
Book a call
Contacts

    Tell us about your project — we'll get back to you within 24 hours.

    replies within 24h

    Thank you!
    Thanks for your email — we will get back to you shortly.