Security Research

The #1 WordPress Hacker This Month Wasn't Human

Patchstack's September 2026 monthly bounty leaderboard showing 440 total reports and Intrudify in first place with 71 reports, ahead of Rafie Muhammad with 37.
Patchstack monthly bounty tournament, September 2026. Captured 30 September 2026.
Key takeaways
  • Intrudify reached the #1 position on Patchstack's September leaderboard with 71 vulnerability reports, against 37 for the researcher in second place.
  • The findings are previously unknown vulnerabilities in real WordPress software, not benchmark or laboratory test cases.
  • Intrudify submitted its first report on September 11.
  • Of the 440 vulnerabilities reported to Patchstack in September, more than 16% came from Intrudify.

AI just reached another milestone in cybersecurity

WordPress powers more than 40% of all websites on the internet. From small businesses and blogs to online stores and major companies, a huge part of the web depends on WordPress and the thousands of plugins built around it.

That scale also makes WordPress an important target for security research. A single vulnerability in a popular plugin can potentially expose hundreds of thousands or even millions of websites.

This month, something unusual happened in that ecosystem.

An AI system did not just finish ahead of the human security researchers hunting for those vulnerabilities. It finished far ahead, with 71 vulnerability reports compared to 37 for the researcher in second place.

And Intrudify only submitted its first report on September 11.

Intrudify reached #1 on Patchstack

Patchstack runs the world's leading bug bounty program for WordPress, bringing together security researchers and ethical hackers from around the world to find previously unknown vulnerabilities before malicious hackers can exploit them.

A bug bounty is essentially a competition to make software safer. Security researchers look for vulnerabilities in real software, report what they discover, and receive recognition and financial rewards when their findings are validated.

The more serious and impactful the vulnerability, the more valuable the discovery.

In September, Intrudify reached the #1 position on Patchstack's monthly leaderboard.

Across the whole programme, 440 vulnerabilities were reported to Patchstack in September. More than 16% of them came from Intrudify.

The difference is that Intrudify is not a human security researcher.

It is an autonomous AI hacking system.

More than 70 new vulnerabilities discovered

Intrudify has now discovered more than 70 previously unknown security vulnerabilities, with the findings receiving CVE identifiers, the global standard used to track publicly disclosed cybersecurity vulnerabilities.

These were not vulnerabilities created specifically for a benchmark or laboratory test.

They were discovered in real software being used by real websites today.

The findings include vulnerabilities in widely deployed WordPress software, including plugins from ecosystems such as Elementor and WooCommerce. Combined, the software affected by Intrudify's discoveries is used across more than 20 million websites.

Some of the vulnerabilities were classified as critical, meaning successful exploitation could have serious consequences for affected websites.

The vulnerabilities were responsibly disclosed so developers could investigate and release fixes before technical details became public.

Why this matters beyond WordPress

For years, penetration testing has depended almost entirely on human expertise.

Companies hire security professionals to attack their applications, discover weaknesses and explain how those weaknesses could be exploited. Good pentesters are extremely valuable, but human testing is expensive, time-consuming and difficult to perform continuously.

AI changes that equation.

The significance of this result isn't simply that Intrudify found dozens of vulnerabilities.

It is that an autonomous AI system competed in the same real-world environment as human security researchers and finished with almost twice as many vulnerability reports as its closest competitor.

This is an important distinction.

Security AI is often evaluated using benchmarks, controlled environments or vulnerabilities that are already known. Real-world vulnerability research is different: the system has to discover something that nobody has reported before and produce enough evidence for independent security researchers to validate it.

That is what happened here.

What happens when AI tries to hack your company?

We built Intrudify around a simple question: what would happen if an autonomous AI tried to hack your company?

Intrudify uses autonomous AI agents to simulate how an attacker would target a company's applications. They explore the application, understand its behavior, identify potential weaknesses and attempt to prove which vulnerabilities can actually be exploited.

Instead of waiting for a real attacker to find those weaknesses, companies can discover them first.

The goal isn't to replace security teams.

It is to show them what an autonomous AI attacker could find in their systems before someone else does.

This is bigger than a leaderboard

Reaching #1 on Patchstack is an important milestone for us. But the bigger story isn't the leaderboard.

It is not even the 70+ previously unknown vulnerabilities.

It's what this result tells us about where cybersecurity is heading.

Until now, sophisticated hacking has been constrained by something very human: the number of skilled people capable of doing it.

AI is beginning to remove that constraint.

This month, an autonomous AI system competed against professional security researchers, searching for previously unknown vulnerabilities in real-world software.

It finished first, with almost twice as many vulnerability reports as its closest competitor.

Today, we're using that capability defensively, to show companies what an AI attacker could discover before a real attacker does.

The question is no longer: Can AI hack?

What could AI hack in your company?

Related reading: Benchmarking Intrudify against two top-tier AI pentesters - How AI is used in cybersecurity - AI vs traditional security testing

Related posts
Security Research Benchmarking Intrudify against two top-tier AI pentesters Pricing Planning Your First Security Budget: A $25,000 Example Startup Security How to Manage Security Without a Dedicated Team
Back to all posts