GPT-5.6 Discovers $500k WordPress RCE Vulnerability for $25

GPT-5.6 Discovers $500k WordPress RCE Vulnerability for $25

First seen 20 Jul 2026, 15:02 UTC News.YcombinatorCybersecuritynews 71% similarity 72.0

Article Content

Browse articles
ThreatCluster

Researchers at Searchlight Cyber utilized GPT-5.6 Sol Ultra to identify a critical pre-authentication remote code execution (RCE) vulnerability in WordPress. The AI model reportedly found the vulnerability after approximately $25 of usage, demonstrating the potential of advanced AI in vulnerability research. The exploit allows attackers to execute code without authentication, posing a significant risk to WordPress instances. The vulnerability was confirmed by independent researchers, and exploit brokers are willing to pay up to $500,000 for the details. Affected systems include all current versions of WordPress. The discovery was made public on July 20, 2026, after researchers allowed time for defenders to upgrade their systems. Tools for checking vulnerabilities have been made available to users.

Key Points: • GPT-5.6 Sol Ultra found a critical RCE vulnerability in WordPress for $25. • Exploit brokers are offering up to $500,000 for details on the vulnerability. • The vulnerability allows pre-authentication code execution, affecting all WordPress versions.

ThreatCluster AI

Timeline

2026-07-20
Vulnerability discovered using GPT-5.6
Searchlight Cyber reported finding a pre-auth RCE vulnerability in WordPress with GPT-5.6 Sol Ultra, costing about $25 in AI usage.
Cybersecuritynews
2026-07-20
Public disclosure of the vulnerability
The vulnerability was disclosed to give defenders time to upgrade their WordPress instances before public knowledge.
News.Ycombinator
Recent
Independent confirmation of the vulnerability
Researchers Calif and Hacktron independently reproduced the exploit before public disclosure, confirming its validity.
News.Ycombinator

Community

Browse all →