Searchlight Cyber researchers used GPT5.6 Sol Ultra from OpenAI to discover a WordPress remote code execution vulnerability for approximately $25 in compute costs. The team adapted a prompt originally released by OpenAI for mathematical problem-solving, directing the model to analyze WordPress source code using multiple agents over six hours. Calif and Hacktron independently reproduced the exploit chain before proof-of-concept code appeared on GitHub. The researchers released a checking tool at wp2shell.com.
No score is assigned. Sources and their independence are shown in the citation chain below.