We built a vulnerability vending machine: AI tokens in, zero-days out
PoC publicCreative Mail WordPress PluginOur summary
A new research project demonstrates how AI can automate the discovery of exploitable vulnerabilities in production software. Using a custom pipeline combining code scanning and large language models, the team at Intruder identified a critical SQL injection flaw in the Creative Mail WordPress Plugin (CVE-2026-3985). The vulnerability allows unauthenticated attackers to extract sensitive data like admin hashes and secret tokens from vulnerable sites. The flaw was exploited using a multi-step attack chain that bypasses traditional detection methods. The plugin has been removed from the WordPress store pending a fix. Users should disable it immediately if running alongside WooCommerce.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.