Exploit brokers pay $500k for WordPress RCEs. I found one with GPT5.6 and $25

A security researcher demonstrates how a sophisticated AI model was used to identify a zero-day vulnerability in WordPress. The author argues that advanced AI agents can significantly lower the barrier for discovering complex software exploits.
Why it matters
This signals a shift in cybersecurity where AI-driven automation could drastically increase the frequency and sophistication of software vulnerability discovery.
If you’re running WordPress and want to check if your instance is vulnerable, you can use our tool we’ve hosted here: https://wp2shell.com/ .
We held off on publishing this issue to give defenders a chance to upgrade their WordPress instances over the weekend, but during that time, Calif and Hacktron were able to independently reproduce the full chain before other PoCs surfaced on GitHub.
Like most security researchers, we follow the new model releases at Searchlight Cyber very closely. When GPT5.6 Sol Ultra was released, we were very excited to test it out.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in