In 90 days the WordPress security program received 2,004 vulnerability reports and paid out over $90,000 for them. That is almost half of everything it has paid since 2017. Until now one party covered the cost: Automattic. On Monday, October 5, 2026, Mary Hubbard, executive director of WordPress, wrote to the heads of more than 30 companies asking them to chip in.
I am basing this on The Repository article of October 8, 2026, which quotes Hubbard’s email (The Repository, October 8, 2026), and on the announcements on wordpress.org. I have not seen the email itself. I checked the figures and quotes against the sources on October 9, 2026.
What Mary Hubbard asked WordPress companies to fund
The email went out to the CEOs of hosting, plugin and security companies on Monday evening UTC. The Repository writes “Monday evening UTC” in its Thursday, October 8 piece. The main thesis: AI has made finding holes cheaper.
“AI had collapsed the cost of finding, reporting, and exploiting vulnerabilities”
Mary Hubbard, quoted by The Repository, October 8, 2026
According to her, the program received almost 2,000 reports in 90 days, more than ever, “and the pace is still climbing”. The Repository checked the program page on HackerOne: 2,004 reports and over $90,000 in bounties in 90 days, against a little over $200,000 paid out since the start in April 2017.
“Nearly half the program’s lifetime payouts happened in a single quarter, and the curve only goes one direction.”
Mary Hubbard, quoted by The Repository, October 8, 2026
Hubbard also writes that Automattic funded the program 100%: every bounty, triage, verification, fixes and coordinated security releases for all supported branches back to WordPress 4.7. She asks for one of three things: a contribution to a shared bounty pool, sponsoring people for triage and releases, or another arrangement worked out together. She stresses that part of the growth is real research that new tools make faster and that genuinely improves security. The problem, in her view, is the economics, not the program itself: “The economics are what’s broken, not the program”.
Which companies were asked to fund WordPress security
GoDaddy, Newfold Digital and Hostinger headed the list of recipients. The Repository goes on to name:
| Group | Companies |
|---|---|
| Hosts and registrars | SiteGround, IONOS, DigitalOcean, DreamHost, World Host Group, Kinsta, OVHcloud, group.one, Namecheap, Tucows, Pantheon, Porkbun |
| Plugins and products | Elementor, Awesome Motive, Incsub (WPMU DEV), Rocketgenius (Gravity Forms), Rank Math, Brainstorm Force, Extendify |
| Enterprise agencies | Human Made, rtCamp |
| Security | Wordfence, Patchstack, BlogVault |
Source: The Repository, October 8, 2026.
The email did not go to WP Engine, which has been in a legal dispute with Automattic since 2024, even though WP Engine representatives were thanked in the credits of the 7.0.2 and 7.1.1 security releases. Nexcess was not on the list either.
How hosts and plugin companies responded
Those who answered The Repository are in favor, but want to know exactly what they would be signing up for.
- Hostinger (Marco Chiesi): considering seconding its own people. Since July it has worked with the security team and deploys WAF rules before patches are published.
- Kinsta (Jon Penland): wants “a clearly defined program” that companies could contribute to.
- Awesome Motive (Syed Balkhi): already sponsors several contributors on the security and plugins teams, but notes that the request is “quite open-ended”.
- Human Made (Tom Willmot): sponsors John Blackbourn, who represents the security team full time. The agency previously tried to rally companies around a security fund, “unfortunately without much traction”.
- Patchstack (Oliver Sild): the company has paid out $600,000 in bounties from its own pocket since 2022, but was never admitted to the WordPress security and plugins teams. In his view “this process needs to be reformed”.
GoDaddy, Newfold Digital and Wordfence had not responded by the time the piece was published.
What WordPress 7.1.3 fixes and who reported the bugs
The day after the email, on October 6, 2026, WordPress 7.1.3 shipped with 7 security fixes and 4 other bug fixes. The announcement credits the reporter for each fix:
| Vulnerability | Who can exploit it | Reporter |
|---|---|---|
| Stored XSS on the Comments screen in the dashboard, via pending comments | Anyone who leaves a comment, if a moderator (Editor or higher) clicks a link in it | Trail of Bits in collaboration with OpenAI |
Denial of service in WP_Http::make_absolute_url() | Contributor account or higher | Anthropic |
| Second-order SQL injection in the WXR export | An Administrator running an export, with a bad _thumbnail_id value already in the database | Anthropic |
| Author could make posts sticky | Author account or higher | Anthropic |
| Disclosure of comments on private and unpublished posts | Anyone, without logging in | Ananda Dhakal, Patchstack |
| XSS in Imgur embeds | Contributor account or higher and a victim who views the post | Zhengyu Liu, Jingcheng Yang, Gavin Zhong |
Forgeable {status}_{type} hook parameters | A plugin passing a raw status or post type to wp_insert_post() | Alex Concha, WordPress security team |
Sources: reporters per WordPress.org, October 6, 2026, exploitation conditions per Patchstack, October 6, 2026.
Only one of the seven holes works with no account and no victim involvement: the leak of comments from private posts. Patchstack explains the mechanism: in the comment feed of a single post, WordPress first fetched the comments and only then checked whether the visitor was allowed to see the post. The check hid the post but not the comments, and feeds do not return a 404, so the comments ended up in the feed. Three of the other six require a Contributor or Author account.
Four of the seven reports come from companies building AI models or their partners. That illustrates Hubbard’s thesis well: AI is now finding holes too, and someone has to pay for each of them with triage, a fix and a release for every supported branch. The announcement says the fixes are being backported to all branches covered by security patches, currently back to 4.7, and will be released as they become ready.
WordPress 7.1.1 and 7.1.2 security fixes
According to Patchstack, release 7.1.2 came out two weeks before 7.1.3 and fixed one vulnerability (CVE-2026-87902). It let an unauthenticated visitor trigger a local file inclusion and, with the right PHP configuration, led to remote code execution (Patchstack, October 6, 2026).
Earlier, in September, Patchstack also described a remote code execution vulnerability patched in 7.1.1. If your site is on 7.1.0, it is missing the fixes from three subsequent releases.
What is the WordPress Core Security Initiative
On August 28, 2026 the security team announced the Core Security Initiative on make.wordpress.org (Make WordPress Security, August 28, 2026). The announcement ties a “substantial increase” in reports to the rapid development of frontier AI models. It describes this as a good problem that nonetheless requires scaling triage, verification and fixing.
The initiative covers WordPress core. It does not cover plugins or themes. Reports are accepted through the HackerOne program, while vulnerabilities in WordPress.com and the mobile apps go separately, through the Automattic program.
What WordPress site owners should do after 7.1.3
Hubbard’s email changes nothing on your site overnight. But the HackerOne numbers and the 7.1.3 list translate into a few concrete things:
- Install 7.1.3 if you have not yet. The announcement recommends updating immediately. Check under Dashboard, Updates that the site really is on 7.1.3, even if you have automatic updates enabled.
- Older branches get patches later. According to Patchstack, on release day the fixes reached branches from 6.6 upward, while branches 4.7 to 6.5 were still waiting. A site on 7.1 was protected from day one.
- Clear the cache after updating. Patchstack warns that 7.1.3 does not remove oEmbed embeds already stored in the database, so a malicious Imgur embed added earlier keeps displaying until you clear the cache.
- Review user roles. Patchstack recommends this explicitly, because three of the seven holes require a Contributor or Author account. Accounts of former authors and agencies that finished work long ago are worth removing or downgrading.
- Core is not everything. The Core Security Initiative does not cover plugins. If you have not reviewed your plugins in a long time, start with an audit of outdated plugins and known CVEs.
- There may be more security releases. Hubbard writes that the pace of reports is still climbing. If you update once a quarter, you can miss several releases in a row. With ongoing WordPress website maintenance, updates are tested on a copy and deployed within days, not months.
If you want to check the state of your site right now, start with a WordPress security audit.
When companies are expected to commit funding
Hubbard offered interested companies detailed program data and wrote that she wants a “first group of contributors standing with us this quarter”, meaning by the end of December 2026. So far no company has publicly announced a specific amount. I will add an update when one does.
Last updated: October 9, 2026.







