News.Ycombinator
GPT-5.6 Discovers $500k WordPress RCE Vulnerability for $25
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Researchers at Searchlight Cyber utilized GPT-5.6 Sol Ultra to identify a critical pre-authentication remote code execution (RCE) vulnerability in WordPress. The AI model reportedly found the vulnerability after approximately $25 of usage, demonstrating the potential of advanced AI in vulnerability research. The exploit allows attackers to execute code without authentication, posing a significant risk to WordPress instances. The vulnerability was confirmed by independent researchers, and exploit brokers are willing to pay up to $500,000 for the details. Affected systems include all current versions of WordPress. The discovery was made public on July 20, 2026, after researchers allowed time for defenders to upgrade their systems. Tools for checking vulnerabilities have been made available to users.
Key Points: • GPT-5.6 Sol Ultra found a critical RCE vulnerability in WordPress for $25. • Exploit brokers are offering up to $500,000 for details on the vulnerability. • The vulnerability allows pre-authentication code execution, affecting all WordPress versions.