• Sources: Searchlight Cyber write-up, CVE-2026-63030 (NVD), HN discussion
  • Summary: Searchlight Cyber published a write-up on 2026-07-20 describing how it found the wp2shell unauthenticated remote-code-execution chain in stock WordPress core using GPT-5.6 Sol Ultra, at a stated pro-rata cost of about 25 USD (50 percent of one week of a 200 USD subscription). The prompt directed the model to analyze source without changelogs or git history, running up to four concurrent agents for at least six hours. The chain pairs a validation-versus-execution desync in the Batch REST API (/wp-json/batch/v1, CVE-2026-63030) with a SQL injection (CVE-2026-60137), which the researcher escalated to admin credential recovery and RCE on a test instance. The flaws affect WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, were disclosed 2026-07-17, and are fixed in 6.9.5 and 7.0.2 with forced auto-updates. No active exploitation is reported.
  • Why it matters: A frontier model locating a critical pre-authentication RCE in the CMS behind a large share of the web, at a cost far below the six-figure exploit-broker prices the write-up cites, is a concrete datapoint on AI-assisted vulnerability discovery against widely deployed software.
  • Follow-up: Watch for reproduction of the discovery method, any exploitation of unpatched 6.9.x or 7.0.x installs, and whether other AI-found core vulnerabilities follow.

send feedback on this story