Exploit brokers are paying up to $500,000 for remote code execution (RCE) vulnerabilities in WordPress, according to security research published on July 20, 2026. A researcher at Searchlight Cyber discovered a WordPress RCE exploit using the GPT5.6 Sol Ultra AI model for just $25, highlighting the growing role of advanced AI in cybersecurity exploits.
The researcher tested the newly released GPT5.6 Sol Ultra model, which had recently solved the Cycle Double Cover conjecture, to develop the exploit. After confirming the vulnerability, the researcher delayed public disclosure to allow WordPress users to patch their systems. Independent researchers Calif and Hacktron were able to reproduce the full exploit chain before proof-of-concept code appeared on GitHub, confirming the exploit’s validity, according to slcyber.io.
This development underscores the increasing sophistication of AI-assisted cyberattacks, where advanced language models like GPT5.6 can be leveraged to create high-value exploits quickly and cheaply. The $500,000 price tag for WordPress RCEs reflects the critical demand for such vulnerabilities in the exploit broker market, which can have significant implications for website security and the broader cybersecurity landscape.
Searchlight Cyber has also hosted a tool at wp2shell.com for WordPress users to check if their instances are vulnerable to this exploit. The disclosure and mitigation efforts around this vulnerability are part of ongoing efforts to protect WordPress installations globally from AI-enabled attack vectors.