All news
cybersecurityregulationsaas

AI Found a $25 WordPress RCE — Hackers Now Exploiting It

24 Jul 2026

A security researcher recently spent just $25 on an AI model to uncover a remote-code-execution (RCE) vulnerability in WordPress — a bug class that exploit brokers reportedly pay up to $500,000 to acquire. That discovery is now colliding with a live, worldwide exploitation campaign targeting two critical WordPress flaws, putting hundreds of millions of websites at risk.

What happened

Last week, WordPress patched two critical security flaws and urged site owners to update immediately, going as far as enabling forced updates where possible. One of the bugs, dubbed WP2Shell, was found and reported by Adam Kues of Searchlight Cyber. Combined, the two flaws let attackers gain full remote control of vulnerable sites.

Despite the patch, cybersecurity firms Patchstack, Hexastrike, and WatchTowr have all warned that hackers are actively exploiting the vulnerabilities — taking over sites that haven't yet updated.

Separately, a researcher used an AI model called GPT5.6 Sol Ultra to independently find a WordPress RCE vulnerability for a total cost of $25 — about 50% of a week's pro-rata usage on a $200 subscription. The researcher spent roughly four hours writing post-exploitation code to escalate a SQL injection bug into full RCE, referencing the WordPress batch API (introduced in WordPress 5.6 back in 2020) as part of the exploit chain. Two other researchers, Calif and Hacktron, independently reproduced the same exploit chain. The original researcher held off publishing details to give defenders a chance to patch over the weekend.

The scale problem

Estimates of how many sites remain exposed vary widely, and sources don't reconcile the numbers:

  • 400 million websites are reportedly running the flawed WordPress versions (6.9.0–6.9.4, 7.0.0–7.0.1).
  • One estimate as of Monday put the number of vulnerable sites at "tens of millions."
  • Cybersecurity consultant Daniel Card sampled around 4,200 WordPress sites and found less than 15% vulnerable — a rate that, projected across the roughly 500 million WordPress installs worldwide, would suggest closer to 90 million vulnerable sites.

Sources differ on which figure best represents real-world exposure, and it remains unclear whether the $500,000 broker price and the $25 discovery cost refer to the same vulnerability or exploit chain. No CVE identifiers have been published for either bug, and the name of the second critical flaw paired with WP2Shell hasn't been disclosed. It's also not clear whether the researcher behind the $25 discovery and Adam Kues of Searchlight Cyber are connected or refer to the same finding.

Why founders should care

If your product or marketing stack runs on WordPress, the practical risk is likely non-trivial: patches exist, but adoption clearly lags — a gap of tens of millions of sites (at minimum) is probably still exposed even after fixes shipped. Founders should treat this as a signal to verify their own WordPress version directly rather than trust any single industry estimate, given how much the reported exposure figures diverge.

There's also a broader, less certain implication: the fact that a serious RCE was found for $25 using an AI model suggests offensive security research may be getting cheaper and more accessible. This could mean startups increasingly need to budget for both AI-assisted penetration testing and stronger defensive monitoring — though how quickly this trend scales beyond isolated cases like this one is not yet established.

What to do now

  • Patch immediately if running WordPress 6.9.0–6.9.4 or 7.0.0–7.0.1; forced updates are being pushed where possible, but don't assume auto-patching covers your setup.
  • Audit your WordPress version directly rather than relying on aggregate vulnerability estimates.
  • Watch for follow-on disclosure — the researcher who found the $25 exploit delayed publication to give defenders time, meaning more technical detail (and likely more opportunistic scanning) may surface soon.
  • Reassess security budgets if you rely on WordPress for revenue-critical infrastructure; the economics of finding these bugs appear to be shifting in attackers' favor as much as defenders'.

Sources