AI Just Made Bug Hunting Cheap. Your Plugin Stack Gets the Bill.

The comforting headline out of Black Hat this year was that AI still cannot hack anything on its own. That is true, and it is the least useful sentence in the story. What actually changed is how much ground one skilled researcher can now cover in a month — and that speed does not belong to the defenders.

“He concluded that AI is perhaps minimally capable but extremely limited in its ability to devise new attack paths in a fully autonomous way. Importantly, though, when paired with human guidance and insight in key moments, Kettle found that AI is an extremely powerful partner in conceptualizing and uncovering new strategies for hacking.”

Lily Hay Newman, WIRED

Our take

<

p class=”wp-block-paragraph”>Read past the reassurance and look at what James Kettle actually built: a productivity multiplier bolted onto a scarce human expert. He describes the system producing notable findings roughly every two days while he was not even logged in, and turning up more proven examples in a few months than he would normally expect from years of work. The bottleneck moved. It used to be “can anyone find bugs here.” Now it is “can anyone review the pile fast enough.”

That matters to a small business for a reason the article never gets to. Vulnerability discovery has always been rationed by expert attention, and expert attention went where the payoff was: major frameworks, popular server software, things with millions of installs. Everything else was safe by neglect. WordPress plugins are the definition of everything else. Most were written by one person, many were last touched years ago, and there are tens of thousands of them.

The numbers in that long tail are already moving. Patchstack logged 11,334 new vulnerabilities across the WordPress ecosystem in 2025, a 42% jump over the prior year, with 91% of them in plugins and only six in WordPress core. Core is fine. Core has never been the problem. The problem is every third-party component you bolt on top of it, each one a separate vendor with a separate and usually nonexistent maintenance budget.

Here is the figure that should change how you actually operate. Patchstack measured a weighted median time from public disclosure to mass exploitation of five hours, with roughly half of high-impact vulnerabilities under attack within a day. Set that against how most agencies work. If you patch client sites on the first Tuesday of the month, your average exposure window on a critical plugin bug is around two weeks. You are running a two-week response against a five-hour clock. That is not a maintenance plan, it is a coin flip you have been winning.

We disagree with how the “human in the loop” finding is being received. It is being read as a limit on AI, which is comforting. Flip it around and it is a description of your disadvantage. The attacking side needs one expert to triage a firehose of machine-generated leads, and Kettle showed one expert is enough. The defending side of a four-person marketing team running thirty client sites has a fraction of a person available, and that fraction is writing content, not reading security advisories. Human-in-the-loop is only reassuring if you have a spare human.

There is a second-order effect in this data that nobody writes about, and it is the sharpest edge in the whole stack: premium plugins with lapsed licenses. Patchstack found that 76% of vulnerabilities in premium and freemium components were exploitable in real attacks, and that premium components carried three times as many known-exploited vulnerabilities as free ones. Premium plugins also stop receiving updates the moment the license expires. So the highest-risk category in the ecosystem is the same category that quietly stops patching when a renewal invoice goes unpaid. That slider bought in 2023 is not a security problem in anyone’s mind. It is a bookkeeping problem, and nobody in the marketing department owns it.

One more thing worth pricing honestly. “Our host handles security” is a measurable claim, and it measures poorly. Patchstack’s testing found hosting defenses blocked only 12% of WordPress-specific vulnerability attacks, and 26% across broader testing, with wide variation between providers. That is not an argument for changing hosts. It is an argument for not treating your host’s firewall as a reason to skip updates.

Kettle’s own discovery — Shared-Parser Confusion, where a web server reuses the same code to handle untrusted requests and trusted responses — is not something you can go fix on a Tuesday. But it is a useful reminder that the catalog of bug categories is not finished. When you cannot predict the shape of the next class of vulnerability, the only durable move is to run less software. Every plugin you delete is a category of future bug you will never have to hear about.

What this means for your business

  1. Turn on automatic updates for every plugin and theme today, and pair it with daily backups. Against a five-hour exploitation window, auto-update plus a restore point beats careful manual review on a monthly schedule for almost every small business. Yes, an update will break something eventually. That is what the backup is for.
  2. Count your plugins and delete a third of them. Deactivated is not removed — the files are still on disk and often still reachable. Uninstall anything you cannot tie to a page, a form, or a number someone looks at.
  3. Pull up every premium plugin license and check the renewal date. An expired license means no security updates on the most exploitable category in the data. The fix here is a credit card, not an engineer, and it is probably the cheapest risk reduction available to you this week.
  4. Point one monitored inbox at a vulnerability feed covering the plugins you actually run. Patchstack and Wordfence both publish free advisories. A shared inbox nobody reads does not count.
  5. Ask your host in writing what share of WordPress-specific attacks their platform blocks, and whether they virtual-patch known plugin vulnerabilities. A specific answer is worth paying for. A vague one tells you the number is low.

None of this requires you to have an opinion about AI. It requires you to assume that finding the bug in your stack just got cheaper for somebody else.

Read Lily Hay Newman’s full report at WIRED.


Put AI to Work for Your Business

MCNM Marketing — the team behind this publication — helps businesses across Las Vegas, Southern California, and Northern Arizona turn stories like this into revenue with AI marketing solutions, SEO & digital strategy, and marketing automation.

Analysis and commentary by MCNM Marketing for Digital Media Marketing & Technology News. The quoted excerpt is from reporting by Lily Hay Newman at WIRED and is used with attribution. Read the full original article at WIRED.

By PTSNV Staff

PTSNV Staff is the newsroom byline of the Philippine Times of Southern Nevada, the bilingual community newspaper serving Filipinos and Filipino-Americans in Las Vegas, Henderson, and North Las Vegas since 2006. Staff reports are written and edited by the newsroom; columns and contributed pieces carry the writer's own byline. Corrections and story tips: editor@ptsnv.com.

Another Website Developed by MCNM LLC.