A newly discovered security vulnerability in WordPress 7.0 has raised concerns among experts regarding the potential for hackers to steal valuable AI API keys from integrated websites.
Key Points
- Patchstack founder Oliver Sild warned that WordPress 7.0 vulnerabilities could lead to a surge in cyberattacks aimed at stealing paid AI API credentials.
- A specific security bug in the WordPress 7.0 AI integration form exposes API keys in plain text via browser autocomplete and autofill suggestions.
- Stolen AI API keys can be used by attackers to power bot networks, conduct large-scale phishing campaigns, or generate malware.
- WordPress co-founder Matt Mullenweg maintains that the majority of WordPress sites remain secure, though developers are debating the need for improved architectural security.
- Experts suggest that the current WordPress plugin trust model may require a more granular permissions system to better protect sensitive credentials from unauthorized access.