On October 6, WordPress rolled out version 7.1.3, patching 7 security vulnerabilities in the platform's core in one go, while also resolving 4 program bugs. Interestingly, among the reporters of these vulnerabilities was a rather unusual name — Anthropic, whose main business is building large language models, contributed 3 of them in one breath. In effect, a company working on frontier AI turned around and became a security guard for the world's most popular site-building system.
Laying out the origins of the vulnerabilities, the lineup is remarkably cross-disciplinary. Of the 7 security vulnerabilities, Anthropic reported 3, security firms Trail of Bits and Patchstack reported 1 each, another 1 was jointly submitted by three independent researchers, and only the final 1 was dug up by WordPress's own security team. In other words, even the maintainer's own team discovered just one of them; the rest all relied on outside eyes keeping watch.
The most dangerous one was hidden in the comment management interface — a stored cross-site scripting (XSS) issue, spotted by Thomas Chauchefoin of Trail of Bits. Its cunning lies in lying dormant: the malicious script first quietly sneaks into the queue of comments awaiting moderation, staying silent as usual, and when an administrator opens the moderation page, it seizes the moment to trigger execution. This wait-and-ambush style of attack specifically targets people with administrative privileges.
Among the 3 vulnerabilities reported by Anthropic, one landed on the WXR exporter. An attacker first stores malicious input inside; left alone it does not fire, and only when a user performs a content export and the system picks up this old input and splices it into a database query does it show its fangs — a back door triggered after a delay. The other two are a denial-of-service vulnerability in the WP_Http::make_absolute_url() method, and a privilege escalation issue where users with the author role could improperly mark posts as sticky; the former can bring the service down under specific requests, while the latter lets ordinary authors, who should not have sticky-post privileges, pry into the publishing schedule.
When a company famous for conversational agents appears on a CMS's vulnerability acknowledgments list, behind it is actually a new pipeline taking shape: AI capabilities trained to find code defects are being deployed directly into real-world combat patrols of the largest, most frequently attacked open source systems. Whether these 3 vulnerabilities were first found by humans or by models, this round of WordPress patches serves as a reminder of an old saying — no matter how popular the foundation, it takes everyone keeping constant watch to keep it from collapsing.