An AI found a $500k WordPress exploit in 10 hours for $25 — and that's the least worrying part
… The SQL injection could fabricate post records returned from the database and place them into WordPress’s temporary in-memory post cache. The model then used WordPress’s embed behavior to turn some of those temporary objects into persistent database records. …