Hourly ·
GPT5.6 Finds WordPress Zero-Day RCE for $25 — Exploit Brokers Pay $500K
Security researcher Adam Kues used GPT5.6 Sol Ultra and a $25 API budget to discover a pre-authentication remote code execution vulnerability in WordPress — the kind exploit brokers pay half a million dollars for.
A security researcher at Searchlight Cyber has demonstrated that frontier AI models can now discover critical zero-day vulnerabilities at a fraction of the cost that exploit brokers pay for them.
Adam Kues used OpenAI's GPT5.6 Sol Ultra with just $25 in API credits and found a pre-authentication remote code execution (RCE) chain in WordPress — the kind of vulnerability that zero-day brokers routinely pay $500,000 or more for on underground markets.
The approach was methodical. Kues took the prompt that OpenAI used to solve the Cycle Double Cover conjecture — a famous mathematical problem — and adapted it for security research. He pointed it at a clean WordPress installation, stripped of git history to prevent the model from "cheating" by diffing against patched versions, and let four AI agents work in parallel for six hours.
The agents explored input parsing, file uploads, serialization, race conditions, and other attack surfaces. The prompt explicitly required them to maintain diverse research routes, cross-pollinate ideas, and use adversarial checking. The result: a full RCE chain that could read arbitrary files from a production WordPress server.
Kues and his team held off publishing to give WordPress administrators time to patch over the weekend. During that window, two other researchers — Calif and Hacktron — independently reproduced the full exploit chain before proofs-of-concept appeared on GitHub, confirming the finding was reproducible and real.
The implications are stark. If a single researcher with a $25 API budget can find a half-million-dollar vulnerability in the world's most widely used CMS — running on over 40% of all websites — the economics of vulnerability discovery have fundamentally shifted. The same technique can be pointed at any codebase. Defenders can use it to find and fix bugs before attackers do; attackers can use it to stockpile zero-days at unprecedented speed and scale.
A verification tool is available at wp2shell.com for WordPress administrators to check if their instances are vulnerable.
Sources: Searchlight Cyber, Hacker News discussion
GPT5.6 发现 WordPress 零日漏洞 RCE,售价 25 美元 —— 漏洞掮客 要价 500 千美元
安全研究员Adam Kues使用GPT5.6 Sol Ultra和25美元API预算是发现WordPress中的一[K 个无认证远程代码执行漏洞——这种类型的恶意软件中间人支付五十万美元。
← 小时精选 小时 · 2026-07-20 16:00 UTC GPT5.6 发现WordPress零日RCE漏洞,花费[K 25美元 —— 这样的 exploit 资产被高价转售至50万美元。 游戏化技术(GPT)研究员[K Adam Kues 使用了 GPT5.6 Sol Ultra 和 25 美元的 API 预算来发现 WordPress 中[K 的一种无需认证的远程代码执行漏洞——这是 Exploit 资产被高价转售至 50 万美元级[K 别的那种。 Searchlight Cyber 的安全研究员还演示了一种前沿的安全实践。
More Hourlies Stories
Content on Anagnorisis is summarized, paraphrased, and editorialized from publicly available sources for length and clarity. Original sources are linked where available. All trademarks belong to their respective owners.
