Exploit brokers pay $500k for WordPress RCEs. I found one with GPT5.6 and $25
# Summary
A security researcher discovered a critical WordPress remote code execution (RCE) vulnerability using OpenAI's GPT5.6 Sol Ultra AI model with a custom prompt, costing only $25—a stark contrast to the $500,000 that exploit brokers typically pay for such vulnerabilities. The researcher adapted a prompt originally used to solve mathematical conjectures for security analysis, directing the AI to use multiple agents to systematically explore WordPress code for zero-day exploits from first principles. The vulnerability was responsibly disclosed to allow defenders time to patch their WordPress instances before public exploit code surfaced.
Read Full Article →