www.infosecurity-magazine.com 7/20/2026, 2:10:51 PM · external

AI crafted WordPress exploit chain triggers urgent CVE patches

AI crafted WordPress exploit chain triggers urgent CVE patches
Developing story malware 10 articles tracked
WordPress core flaws CVE-2026-60137 and CVE-2026-63030 exploited in the wild
CyberSIXT Evidence Panel
Primary Source slcyber.io
CISA KEV Not in KEV
Patch Patch Status Unknown

SECURITY researchers at Searchlight Cyber have developed a complete exploit chain for two critical vulnerabilities in WordPress, utilizing OpenAI’s GPT-5.6 Sol Ultra. The vulnerabilities, identified as CVE-2026-63030 and CVE-2026-60137, affect multiple WordPress Core versions and can lead to pre-authentication remote code execution. The exploit, named 'WP2Shell,' allows unauthenticated users to exploit default WordPress installations without any plugins.

The researchers demonstrated the capabilities of the AI model in creating a complex chain of exploits, achieving results in about ten hours with minimal costs. WordPress responded by forcing automatic updates to patch the vulnerabilities, while a scanning tool was released by Searchlight Cyber to assist server administrators in checking for vulnerabilities.

View Primary Source Via www.infosecurity-magazine.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline