GPT-5.6 Sol Ultra Found and Weaponized a WordPress Core RCE for $25 in Ten Hours
Searchlight Cyber adapted OpenAI's published vulnerability-research prompt, pointed four agents at WordPress Core for six-plus hours, and got a full pre-auth exploit chain: CVE-2026-63030 (REST API batch endpoint route confusion, CVSS 9.8) escalated via CVE-2026-60137 (author__not_in WP_Query SQLi). Total compute cost was roughly $25 over ten hours against a market where exploit brokers pay $500,000 for a WordPress RCE. The chain — dubbed 'wp2shell' — poisons the oembed cache, abuses customize_changeset to temporarily assume admin, and uses a cycle-detection gadget to re-trigger parse_request, create an admin account, and upload a backdoor plugin; 500M+ sites affected, emergency patch 7.0.2 released.
↳ Follow the thread