Fetching from the wire…
Public story · 2026-07-20 · high
Searchlight Cyber chained two CVEs into a full pre-auth exploit in six hours, and the exploit-broker price for this bug is $500,000.
Why now: Covered in the 2026-07-20 briefing, with the emergency patch already out.
Searchlight Cyber pointed four GPT-5.6 Sol Ultra agents at WordPress Core. Using OpenAI's published vulnerability-research prompt, they had a working pre-auth exploit chain in six-plus hours, for about $25 in compute.
The chain, which they're calling wp2shell, links two CVEs. CVE-2026-63030 is a route confusion bug in the REST API's batch endpoint, CVSS 9.8. It escalates through CVE-2026-60137, a SQL injection in the author__not_in parameter of WP_Query.
Chained together, the agents poison the oembed cache and abuse customize_changeset to briefly assume admin. Then a cycle-detection gadget re-triggers parse_request, creates a real admin account, and drops a backdoor plugin. WordPress Core runs 500 million-plus sites, and patch 7.0.2 is out now.
Exploit brokers pay $500,000 for a WordPress RCE of this quality, per Searchlight Cyber. This one cost $25 and six hours of agent time, a ratio worth sitting with.
That ratio is the number defenders should plan around, not treat as a one-off headline. Finding a critical pre-auth chain in WordPress Core used to require real skill and real time. Now it requires patience and a credit card.
Patch 7.0.2 if you run WordPress anywhere, including that marketing site you forgot about. Searchlight Cyber's writeup doesn't say how many other CMS platforms would fold to the same prompt, and that's the open question worth watching.
Each link below shares sources, entities, or timing with this story.
OpenAI partners with AWS / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (OpenAI partners with AWS); both cover CVE, CVSS, OpenAI; overlapping topics (agent, hour).
OpenAI supports MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (OpenAI supports MCP); both cover CVE, CVSS; overlapping topics (agent, backdoor, chain).
OpenAI released Frontier / Shared entities / Earlier coverage
Linked by a graph relationship (OpenAI released Frontier); both cover GPT, OpenAI, Sol Ultra; earlier GPT coverage from 2026-07-11.
LiteLLM supports OpenAI / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (LiteLLM supports OpenAI); both cover CVE, CVSS; overlapping topics (agent, chain).
OpenAI uses Azure / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (OpenAI uses Azure); both cover CVE, CVSS; overlapping topics (admin, chain).
Microsoft competes with OpenAI / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Microsoft competes with OpenAI); both cover CVE, CVSS; overlapping topics (agent, chain).
Anthropic partners with OpenAI / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Anthropic partners with OpenAI); both cover GPT, OpenAI; overlapping topics (agent, hour).
Linked by a graph relationship (Anthropic partners with OpenAI); both cover CVSS, OpenAI; overlapping topics (account, hour).