← Back to the wire

Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25 › Searchlight Cyber

AchievementResearchJul 20, 2026

Searchlight Cyber researchers used GPT5.6 Sol Ultra from OpenAI to discover a WordPress remote code execution vulnerability for approximately $25 in compute costs. The team adapted a prompt originally released by OpenAI for mathematical problem-solving, directing the model to analyze WordPress source code using multiple agents over six hours. Calif and Hacktron independently reproduced the exploit chain before proof-of-concept code appeared on GitHub. The researchers released a checking tool at wp2shell.com.

Receipt № 7621 source · awaiting confirmation ◐

Evidence

1source· awaiting independent confirmation

No score is assigned. Sources and their independence are shown in the citation chain below.

Citation chain · 1 source

OpenAICompanyGitHubCompanySearchlight CyberCompanyWordPressCompanyHacktronCompanyGPT5.6 Sol UltraModelCalifPerson
Canonical: https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/