CVE Tools

We built a vulnerability vending machine: AI tokens in, zero-days out

BleepingComputerBy Intruder

PoC publicCreative Mail WordPress Plugin

Our summary

A new research project demonstrates how AI can automate the discovery of exploitable vulnerabilities in production software. Using a custom pipeline combining code scanning and large language models, the team at Intruder identified a critical SQL injection flaw in the Creative Mail WordPress Plugin (CVE-2026-3985). The vulnerability allows unauthenticated attackers to extract sensitive data like admin hashes and secret tokens from vulnerable sites. The flaw was exploited using a multi-step attack chain that bypasses traditional detection methods. The plugin has been removed from the WordPress store pending a fix. Users should disable it immediately if running alongside WooCommerce.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store