Over the past year, the WordPress project has seen a substantial increase in the volume of incoming security reports. Much of this growth reflects the rapid advancement of frontier AI models and their growing capability to assist with security research: it has never been easier to analyze code for potential vulnerabilities, and reporting volume across the whole WordPress ecosystem has risen accordingly.
This is a good problem to have: more eyes on WordPress makes WordPress safer, but it requires the project to scale how we triage, validate, and resolve what comes in. The topic came up during the security team meeting at WordCamp US last week, and today we’re sharing more about the work underway.
The security team has begun a coordinated effort called the CoreCore Core is the set of software required to run WordPress. The Core Development Team builds WordPress. Security Initiative with one goal: a stronger, safer WordPress. It focuses a coordinated effort under three pillars: ABC.
A better release process
Building a tighter, more automated security release process, with improved end-to-end testing, so fixes ship reliably and predictably. The security team is scheduling upcoming security releases as a result.
Breaking the backlog
Bringing on more team members and volunteers to work through the queue of open reports and known issues, with the aim of driving open findings down to zero.
Crush vulnerabilities with AI
Applying AI-assisted scanning and tooling to find vulnerabilities before they can be exploited, complementing the reports received through responsible disclosure.
This work is supported by the WordPress core security team, longtime core contributorsCore Contributors Core contributors are those who have worked on a release of WordPress, by creating the functions or finding and patching bugs. These contributions are done through Trac. https://core.trac.wordpress.org, and contributors sponsored by companies across the WordPress ecosystem.
How you can help
Security research and responsible disclosure remain the front line. If you believe you’ve found a vulnerability in WordPress core, please report it through the official channel at hackerone.com/wordpress and please review the reporting guidelines before submitting, as report quality matters more than ever at this volume.