SECURITY researchers at Searchlight Cyber have developed a complete exploit chain for two critical vulnerabilities in WordPress, utilizing OpenAI’s GPT-5.6 Sol Ultra. The vulnerabilities, identified as CVE-2026-63030 and CVE-2026-60137, affect multiple WordPress Core versions and can lead to pre-authentication remote code execution. The exploit, named 'WP2Shell,' allows unauthenticated users to exploit default WordPress installations without any plugins.
The researchers demonstrated the capabilities of the AI model in creating a complex chain of exploits, achieving results in about ten hours with minimal costs. WordPress responded by forcing automatic updates to patch the vulnerabilities, while a scanning tool was released by Searchlight Cyber to assist server administrators in checking for vulnerabilities.