
Aaron D. Campbell says WordPress security is entering a faster, more complicated era, driven in large part by AI. In a WP Tavern Jukebox Podcast episode recorded at WordCamp US, Campbell described how attackers and defenders are now locked in an arms race where machine speed, not just human skill, increasingly determines who stays ahead.
Aaron D. Campbell on the changing WordPress security landscape
Campbell brings more than 25 years of experience in the internet and WordPress world, spanning agency work, security products, and hosting roles at GoDaddy, Newfold, and hosting.com. He also led the WordPress Security Team and now works at Monarx, a company focused on malware detection and remediation for web hosts.
At Monarx, Campbell said the company is often invisible to end users because its services are commonly white-labelled by hosting providers. Those hosts may bundle malware detection, runtime monitoring, firewall protection, and remediation into their own plans, with Monarx operating in the background.
That placement gives the company a broad view of attacks across multiple hosting environments. According to Campbell, that matters because threats often appear in one corner of the ecosystem and then spread quickly elsewhere.
Why AI has changed the pace of attacks
Campbell said AI has not changed the basic attacker-versus-defender dynamic, but it has dramatically increased speed, scale, and complexity. Tasks that once required human ingenuity can now be automated by AI systems that scan code, find potential weaknesses, and chain together exploit steps at a pace that would be difficult for people to match.
He pointed to a recent WordPress Core report that required printing out an 11-page description just to understand the sequence of steps involved. What might once have looked like a secure code path can now be turned into a practical exploit when AI stitches together the logic and turns it into automation.
The result, Campbell said, is a flood of issues arriving more quickly and in more complicated forms than before. That puts software teams, SaaS vendors, and hosting companies on the defensive, often before they have time to fully assess what they are facing.
From weeks to hours, and possibly less
One of the clearest signs of the shift is the shrinking window between vulnerability disclosure and real-world exploitation. Campbell said the industry moved from having weeks to respond, then days, and now often only hours for major vulnerabilities.
He cited a Monarx and Patchstack year-in-review that found the most significant vulnerabilities were being exploited in about five hours. In the case of the recent wp2shell WordPress exploit, Monarx observed a sharp spike in exploitation within about 30 minutes of the patch and public information being released.
That does not yet mean every flaw is weaponized within seconds, he said, but it does suggest the window will likely keep shrinking.
AI versus AI in WordPress security
Campbell said defenders are now using AI as well, both to analyze attacker reports and to test whether vulnerabilities are real. He described building AI-assisted testing rigs that can evaluate reports, examine repositories, and check whether a vulnerability requires authentication or follows a viable attack path.
In his view, AI has become a tool to combat AI. Human judgment still matters, especially when deciding how a fix should behave and whether it is forward-looking enough, but the logical heavy lifting is increasingly being handled by machines.
He also said collaboration is essential. Attackers share information with one another, and security teams must do the same if they want to keep pace. That includes the WordPress Security Team sharing information privately with hosts, Cloudflare, and other security groups so protections can be deployed before public releases reach every site.
Why WordPress remains a target
Campbell said WordPress is attractive to attackers largely because of scale. As the most popular CMS on the web, it offers a massive potential payoff if a vulnerability affects tens of millions of sites.
That payoff is not limited to stealing data from a single site. A compromised WordPress installation can be used to serve pay-per-click spam, inject malicious scripts, or provide distributed compute power for attacking other targets. Even sites with little traffic can still be useful as part of a much larger malicious network.
He emphasized that the motive is usually money. Political or ideological attacks do happen, but most abuse can still be traced back to financial gain somewhere in the chain.
Supply chain attacks and the “Protect the Shire” approach
Campbell said one of the biggest trends now is the rise of supply chain attacks, where attackers compromise a package, plugin, or other trusted component and use that access to reach many downstream sites.
That is where WordPress’s “Protect the Shire” innovation comes in. The system introduces a six-hour waiting period before some plugin updates can be applied, giving security teams time to identify whether an update is legitimate or part of a compromise.
Campbell said the idea is a good one, but not something that should be treated as inflexible. If a plugin has a genuine security flaw, the WordPress Security Team can coordinate a faster release or make an exception when necessary. In his view, the delay helps balance rapid updates against the risk of malicious tampering.
Practical advice for everyday WordPress users
For regular site owners, Campbell’s advice is simple: rely on experts wherever possible. He urged users to keep WordPress auto-updates turned on so they benefit from the work of the WordPress Security Team as quickly as possible.
He also recommended choosing a security-minded host and asking what layers of protection are in place. In his view, layered security is the right model: a secure platform, a secure host, and additional safeguards working together.
- Enable WordPress auto-updates so core fixes land quickly.
- Choose a host with visible security controls and layered protection.
- Check whether your credentials have appeared in breach data.
Campbell’s third recommendation was to monitor for compromised credentials, including through services such as Have I Been Pwned. He said AI is particularly good at collating old breach data and using it to test whether reused passwords still work across different services years later.
That makes credential hygiene more important than ever. Even if an old password leak seems irrelevant, attackers can use it to probe email accounts, hosting logins, bank sites, and social media accounts with surprising precision.
A field that rewards constant adaptation
Campbell said he still sees open source, and WordPress in particular, as a stronger model for security because so many people can inspect the code, report issues, and contribute fixes. He argued that openness makes software more resilient, not less, even if attackers can also study the code.
He does not expect the current situation to resolve overnight. In fact, he said the industry may have to endure more turbulence before conditions improve. But he believes the work being done now, especially around shared intelligence and AI-assisted defense, is laying the foundation for a better future.
For Campbell, the challenge is also part of the appeal. He compared the work to playing a demanding game of chess against a strong opponent: exhausting at times, but deeply rewarding when a difficult problem is solved. And if the security industry ever does become so effective that he works himself out of a job, he said that would be the best possible outcome.
Source: Original report
Was this helpful?
Explore more: WordPress Troubleshooting More WordPress & CMS Tech News
Last Modified: September 3, 2026 at 1:53 am
3 views

