GPT-5.6 Found a $500,000 WordPress RCE for $25 — and It Took 10 Hours Searchlight Cyber researcher Adam Kues spent $25 of GPT-5.6 Sol Ultra tokens and 10 hours of multi-agent analysis to discover CVE-2026-63030 ('wp2shell'), a pre-authentication SQLi-to-RCE chain in WordPress core affecting over 500 million sites. The bug exploits a REST API batch endpoint validation/execution desync with cache poisoning, and exploit brokers pay $500,000 for WordPress pre-auth RCEs — a 20,000x cost-to-payout inversion. WordPress patched it in versions 6.9.5 and 7.0.2 on July 17. GPT-5.6 Found a $500,000 WordPress RCE for $25 — and It Took 10 Hours Searchlight Cyber's Adam Kues spent $25 of GPT-5.6 Sol Ultra tokens and 10 hours of multi-agent analysis to discover CVE-2026-63030 'wp2shell' , a pre-authentication SQLi-to-RCE chain in WordPress core affecting 500M+ sites. The bug exploits a REST API batch endpoint validation/execution desync with cache poisoning. Exploit brokers pay $500K for WordPress pre-auth RCEs — a 20,000x cost-to-payout inversion. WordPress patched it in 6.9.5 and 7.0.2 on July 17. A security researcher spent $25 of GPT /glossary/gpt -5.6 Sol Ultra tokens and ten hours of multi-agent analysis. The result: a pre-authentication remote code execution chain in WordPress core — CVE-2026-63030, now known as "wp2shell" — that affects over 500 million websites and carries a $500,000 bounty on exploit markets. Adam Kues of Searchlight Cyber published the full writeup on July 17, and it's the most consequential demonstration yet of AI-assisted vulnerability discovery at scale. He adapted OpenAI /glossary/openai 's Cycle Double Cover conjecture-solving prompt — a multi-agent research framework originally built for pure mathematics — pointed it at the WordPress codebase, and let four parallel agents run for at least six hours each. <<