ctipilot.ch
← Back to the live brief
NOTABLEupdateNATOB2research

AI-accelerated exploit dev: GPT5.6 autonomously rediscovers and weaponises the WP2Shell WordPress RCE chain in ~10h for ~$25

discovered 2026-07-21 04:44 UTCrun 2026-07-21T0409Z-intel2 sourcesmulti-source

UPDATE · originally covered WP2Shell: pre-auth RCE chain in stock WordPress core (CVE-2026-63030 + CVE-2026-60137) — out-of-band 7.0.2 patch, exploitation expected short-term (2026-07-18)

Searchlight Cyber's Adam Kues tasked OpenAI's GPT5.6 model — running autonomously for up to 10 hours per session — to independently rediscover and weaponise "WP2Shell", the WordPress core pre-authentication RCE chain this pipeline covered on 2026-07-18 (CVE-2026-63030, a REST batch-endpoint route-confusion flaw, chained with CVE-2026-60137, an SQL injection in WP_Query's author__not_in parameter; both patched out of band in WordPress 7.0.2/6.9.5/6.8.6 on 2026-07-17). Without human guidance beyond the initial task, the model recursively chained batch API requests to bypass method validation, poisoned the request cache with fabricated posts, abused the oEmbed subsystem to insert database rows, and replayed a request with elevated administrator context via the parse_request hook — ending with an unauthorised admin account on a stock, plugin-free install (Searchlight Cyber, 2026-07-20). Kues put the cost at roughly $25 — "50% of weekly usage ... ~ $25 USD" on a $200 subscription — and states plainly that "no security researcher could have found and completed this exploit chain in 10 hours without AI." Infosecurity Magazine corroborates (Infosecurity Magazine, 2026-07-20).

Nothing about the CVEs, affected versions or patch guidance has changed — this is a capability finding, not a new vulnerability.

Total usage: 50% of weekly usage. Pro-rata total cost on the $200 subscription: ~ $25 USD.

No security researcher could have found and completed this exploit chain in 10 hours without AI.

Searchlight Cyber 2026-07-20

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.1

Initial Access TA0001
T1190Exploit Public-Facing Application

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.