Following an increase in security reports linked in part to the growing capabilities of AI models in security research, the WordPress security team has announced the Core Security Initiative. The announcement follows a discussion about the issue during the security team’s meeting at WordCamp US last week.
Three pillars form the Core Security Initiative
Rudy Faile (Senior Systems Engineer at Automattic) pointed to the increase in security reports and the role AI is playing in security research. He wrote that “Over the past year, the WordPress project has seen a substantial increase in the volume of incoming security reports. Much of this growth reflects the rapid advancement of frontier AI models and their growing capability to assist with security research:”
Faile also highlighted how AI has changed the process of finding potential vulnerabilities, saying that “it has never been easier to analyze code for potential vulnerabilities, and reporting volume across the whole WordPress ecosystem has risen accordingly.”
He described the increase in security reports as a positive development, while noting that the higher volume also requires the project to scale how it handles incoming reports, “This is a good problem to have: more eyes on WordPress makes WordPress safer, but it requires the project to scale how we triage, validate, and resolve what comes in.”
The Core Security Initiative is organized around three pillars, referred to as “ABC”. These cover strengthening the security release process through automation and testing, adding team members and volunteers to address the backlog of open reports and known issues, and using AI-assisted scanning and tooling to identify vulnerabilities before they can be exploited.
The announcement also calls on the community to continue supporting the effort through security research and responsible disclosure. Anyone who believes they have found a vulnerability in WordPress core can report it through the official HackerOne channel, while the security team asks researchers to review the reporting guidelines before submitting. The announcement notes that “report quality matters more than ever at this volume.”
The new initiative comes after WordPress received three security releases in less than a month: 7.0.2 on July 17, 7.0.3 on August 6, and 7.0.4 on August 12. Notably, AI was involved in finding the vulnerability reported in WordPress 7.0.2, where the security researcher used GPT5.6 Sol Ultra.