An AI Model Found the WordPress Flaw in Ten Hours for $25. Attackers Weaponized the Patch in Ninety Minutes.

WordPress released 7.0.3 on August 6, a security release the core team recommends installing immediately. Its headline entry is a pre-auth reflected cross-site scripting flaw on the login screen that can lead to PHP code execution, reported by the team at pwn.ai and tracked as CVE-2026-64638. It is the second such release in three weeks, and the … Continue reading An AI Model Found the WordPress Flaw in Ten Hours for $25. Attackers Weaponized the Patch in Ninety Minutes.