WordPress has launched the Core Security Initiative, a program designed to accelerate the security process surrounding the CMS’s core. It is based on three pillars: a more rigorous release process, clearing the backlog of reports, and AI-driven vulnerability scanning to identify vulnerabilities before attackers do.
AI makes it easier to detect vulnerabilities and exploit them quickly. This has led to a significant increase in reports compared to what the security team was used to handling. WordPress has therefore decided to deploy that same technology itself.
The initiative focuses exclusively on WordPress core, the software powering millions of installations worldwide as the backend for websites. It is led by the core security team, supplemented by long-term contributors and corporate-sponsored developers. In the announcement, the team refers to “breaking the backlog” of vulnerabilities.
Three pillars
The first pillar is a more reliable and automated release process, with improved end-to-end testing to ensure predictable rollouts of fixes. The second aims to clear the backlog of open reports, moving toward zero open findings. The third pillar is AI-assisted scanning, complementing the existing responsible disclosure process.
Until now, WordPress has relied primarily on external researchers and security firms to find vulnerabilities. That approach is now becoming proactive. Given the speed of cyberattacks, this seems simply necessary and sets an example that other widely used solutions will have to follow.
Pressure on the ecosystem
This month, WordPress 7.0.3 was released with twelve security fixes, followed shortly thereafter by 7.0.4 with an additional patch. The Canadian government reported that core vulnerabilities were being actively exploited.
Incidentally, the greatest risk does not lie in the core. According to Patchstack, 11,334 new vulnerabilities were uncovered in the WordPress ecosystem in 2025, 91 percent of which were in plugins and 9 percent in themes. Such cyber threats are widespread. Consider, for example, vulnerabilities that affected a million sites through a single plugin.