Five Hours to Mass Exploitation: How AI Changed the Speed of WordPress Attacks
WordPress security used to run on a comfortable cycle: a flaw is disclosed, a patch appears, owners update eventually.
Patchstack’s State of WordPress Security in 2026 puts the median gap between disclosure of a critical flaw and mass exploitation at five hours. Eleven thousand vulnerabilities were logged in 2025, nine in ten in plugins, and nearly half had no fix on the day they went public.
The driver is automation: a patch goes into AI tooling and scanners sweep the internet hours later.
Two things still work. Auto-updates, with staging behind them. And a firewall — when a flaw ships without a patch, a WAF rule is often the only protection there is.