HeadlinesBriefing favicon HeadlinesBriefing.com

WordPress RCE Exploit Costs $500k Brokers

Hacker News •
×

If you’re running WordPress and want to check for vulnerabilities, you can use our tool hosted at https://wp2shell.com/. We held off publishing the issue to give defenders a chance to upgrade over the weekend, but Calif and Hacktron independently reproduced the full chain before other PoCs surfaced on GitHub.

Like most researchers, we follow new model releases at Searchlight Cyber closely. When GPT5.6 Sol Ultra launched, we tested it. Sol had solved the Cycle Double Cover conjecture and published its prompt. We adapted that prompt, targeting WordPress with four agents for six hours, asking it to discover a pre‑auth to RCE chain.

Output showed a pre‑auth SQL injection. After installing a stock WordPress instance, Sol extracted the admin email and later confirmed that the read‑only SQLi could elevate to admin without cracking passwords. Total usage was 50 % of the week's, costing about $25 on a $200 subscription.

The bug lies in the batch API introduced in WordPress 5.6. The endpoint accepts multiple virtual API requests without authentication, passing subrequest credentials. Sol’s chain exploited this to reach an RCE, revealing a flaw present in over 500 million installations worldwide.