HomeRisk ManagementsResearchers Develop WordPress Exploit Leveraging OpenAI's GPT

Researchers Develop WordPress Exploit Leveraging OpenAI’s GPT

Published on

spot_img

Security Researchers Harness AI to Uncover Critical WordPress Exploits

In a groundbreaking development within the cybersecurity landscape, researchers from Searchlight Cyber have successfully utilized OpenAI’s advanced GPT-5.6 Sol Ultra to identify a comprehensive exploit chain targeting two critical vulnerabilities in WordPress Core. This innovative application of artificial intelligence marks a significant leap forward in the quest to secure widely used web applications.

The first vulnerability, designated CVE-2026-63030, pertains to a significant misrouting issue within the REST API batch endpoint, which has garnered a critical CVSS rating of 9.8. It affects various versions of WordPress Core, specifically versions 6.9.x prior to 6.9.5 and 7.0.x before the release of version 7.0.2.

The second vulnerability, known as CVE-2026-60137, involves a high-severity SQL injection flaw categorized under WP_Query. This vulnerability carries a CVSS rating of 5.9 and impacts WordPress Core versions 6.8.x prior to 6.8.6, alongside the same 6.9.x and 7.0.x versions mentioned above.

In response to these serious vulnerabilities, WordPress released version 7.0.2 of its content management system on July 17, aimed explicitly at remedying these threats. Notably, by chaining the exploits associated with both vulnerabilities, attackers can achieve pre-authentication remote code execution in WordPress installations operating on versions 6.9.x and 7.0.x.

Searchlight Cyber’s team, who initially discovered CVE-2026-63030, has dubbed their combined exploit "WP2Shell," as detailed in an advisory they published on July 17. Unlike many previous vulnerabilities, WP2Shell affects the WordPress Core itself rather than third-party plugins or themes, permitting unauthenticated attackers to exploit it against standard WordPress installations devoid of modifications.

Adam Kues, a security researcher at Searchlight Cyber, highlighted the gravity of this exploit: "The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins,” emphasizing the ease with which potential attackers could exploit this vulnerability.

AI Unveils Complicated Pre-Authentication RCE Chain

In a report published on July 20, Kues illustrated how he employed GPT-5.6 Sol Ultra, the latest AI offering from OpenAI, which is accessible through ChatGPT Work Pro and Enterprise, as well as Codex Plus plans. The AI was prompted using methodologies previously utilized to resolve complex mathematical conjectures, steering it towards finding an exploit chain within WordPress.

Kues meticulously removed the version history from a pristine copy of the WordPress source code to prevent the AI from leveraging any prior knowledge. He instructed the model to operate up to four independent agents for a duration of at least six hours to seek out a pre-authentication remote code execution pathway. The model swiftly identified the REST API batch route confusion issue (CVE-2026-63030), recognizing that a desynchronization between user input validation and execution processes allowed it to bypass input sanitization, consequently triggering the SQL injection related to CVE-2026-60137.

Within mere minutes, the model applied this SQL injection to extract the administrator’s email from a newly set-up WordPress installation. However, the true spectacle of the AI’s prowess lay in its ability to escalate this read-only database access into full remote code execution.

Over a subsequent four-hour period, the AI developed an intricate, multi-stage exploit chain, utilizing cache poisoning techniques with fabricated oEmbed entries, manipulating WordPress customizer changesets to grant itself temporary administrative privileges, and triggering hooks that enabled it to bypass authentication entirely, thus allowing it to upload a backdoor plugin.

This entire automated exploit process took just over ten hours and cost approximately $25 in computational resources. Such a feat underscores the profound implications of artificial intelligence in cybersecurity; Kues noted that replicating this process manually would have likely necessitated weeks, if not months, for a human security researcher. "No security researcher could have found and completed this exploit chain in 10 hours without AI," he remarked.

With exploit brokers reportedly willing to shell out up to $500,000 for an undeclared zero-day remote code execution vulnerability in WordPress Core, Kues emphasized that the capability of an off-the-shelf AI model to discover such a vulnerability for a fraction of the cost signifies a paradigm shift in cybersecurity economics.

In the wake of the public disclosure of the two WordPress Core vulnerabilities, several additional security researchers have begun to release proof-of-concept exploits. Moreover, on the same day as the exploit’s disclosure, the security firm PatchStack reported instances of exploitation relating to both CVEs, though the specifics of the in-the-wild exploitation remain ambiguous.

Other companies, including Hexastrike and WatchTowr, have also observed indications of attempts to exploit these vulnerabilities in real-world scenarios.

Immediate Action from WordPress to Mitigate Threats

Reacting swiftly to the potential threats presented by WP2Shell, WordPress implemented an unusual measure by forcing automatic updates for affected installations to promptly diminish the risk. Users are advised to manually verify that their sites are running either version 7.0.2 or the preceding version 6.9.5.

To further assist administrators in securing their websites, Searchlight Cyber has introduced a complimentary scanning tool available at wp2shell.com. This tool allows site managers to safely assess whether their servers remain susceptible to this AI-generated attack.

As the landscape of cybersecurity continues to evolve, the integration of AI technologies into vulnerability discovery and exploitation introduces both unprecedented challenges and transformative opportunities for securing digital platforms against malicious threats.

Source link

Latest articles

Russian Hacker Transforms Jailbroken Claude into Penetration Testing Platform

Rapid Evolution of Cybercrime: From Tutorial to Commercial Product In a remarkable instance of the...

Cyber Briefing – July 21, 2026 – CyberMaterial

Cybersecurity Updates: Recent Threats and Policies Recent developments in cybersecurity are raising alarms across various...

US Transfers AI Governance Responsibilities to Others

US Government Lags Behind in AI Governance as China and Major Tech Firms Advance As...

CISA Warns of Targeted Attacks by Russian FSB Hackers on Critical Infrastructure Routers

The Cybersecurity Threat Landscape: Addressing Vulnerabilities and Protecting Critical Infrastructure The Russian Federal Security Service...

More like this

Russian Hacker Transforms Jailbroken Claude into Penetration Testing Platform

Rapid Evolution of Cybercrime: From Tutorial to Commercial Product In a remarkable instance of the...

Cyber Briefing – July 21, 2026 – CyberMaterial

Cybersecurity Updates: Recent Threats and Policies Recent developments in cybersecurity are raising alarms across various...

US Transfers AI Governance Responsibilities to Others

US Government Lags Behind in AI Governance as China and Major Tech Firms Advance As...