title: “$25 of GPT-5.6 Sol Ultra found a pre-auth WordPress RCE — Searchlight Cyber’s wp2shell”
Exploit brokers pay around $500,000 for a WordPress pre-auth RCE. Adam Kues at Searchlight Cyber got one for $25 in API spend — half a day of GPT-5.6 Sol Ultra, no human bug hunting.
What it actually is
Not a product. A methodology, plus the bug it produced. Kues took the multi-agent prompt harness OpenAI used on the Cycle Double Cover math proof, pointed it at a local checkout of WordPress core, and let four agents grind for about ten hours. Out came wp2shell: an offset mismatch between validation and execution in the REST batch API, an unauthenticated SQL injection in the posts endpoint, memory-cache poisoning to forge a post, changeset abuse for temporary admin, then arbitrary hook execution. CVE-2026-63030 and CVE-2026-60137, patched in 7.0.2 and 6.9.5. Default installs. 500 million+ instances.
Why the $25 matters more than the bug
The bug gets patched. The cost curve doesn’t un-happen. A $200/month subscription now buys roughly two shots at a half-million-dollar vulnerability class, and the harness is public and reproducible. HN put it at 296 points and 161 comments the day it landed — the loudest AI story of July 20.
Every attacker with a credit card just got the same tooling as the defenders.
You Might Also Like
- Gpt 5 6 sol Ultra Proves the 50 Year old Cycle Double Cover Conjecture 24 Hours After ga
- Openai Trusted Access for Cyber Opens gpt 5 5 to Offensive Security Work for Verified Defenders Only
- Openai gpt Realtime 2 Translate Whisper Three Voice Models one api Several Startups Erased
- Gpt 5 5 Cyber Openai Forks a Security Model With Looser Guardrails for Vetted red Teams
- Openai gpt 5 6 sol Terra Luna a Three Tier Lineup Only 20 Orgs can Touch

Leave a comment