Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI Discovers WordPress Flaw, Potentially Worth 0,000

AI Discovers WordPress Flaw, Potentially Worth $500,000

Posted on July 20, 2026 By CWS

In a significant leap for cybersecurity, GPT-5.6 Sol Ultra, an advanced AI model, has reportedly identified a critical remote code execution (RCE) flaw in WordPress. The breakthrough was achieved using just $25 worth of AI resources, illustrating the potential of AI in vulnerability detection.

Advanced AI Models in Cybersecurity

Researchers at Searchlight Cyber employed GPT-5.6 Sol Ultra to scrutinize a local copy of WordPress’s source code. The model, with the help of four AI agents, diligently worked for over six hours to uncover this major vulnerability.

The AI unearthed an exploit chain that could let unauthorized attackers obtain administrative access and execute arbitrary code on susceptible WordPress sites. This discovery highlights the evolving role of AI in identifying and mitigating cybersecurity threats.

The Value of the Discovered Vulnerability

The potential impact of this vulnerability is substantial, with researchers estimating damages up to $500,000. This figure underscores the value of RCE vulnerabilities, particularly those affecting widely adopted platforms like WordPress.

Given that WordPress supports over 500 million websites worldwide, a default-configuration RCE poses a significant risk. The reported flaw centers around WordPress’s Batch API, accessible via the /wp-json/batch/v1 endpoint, which processes multiple REST requests within a single HTTP request.

Technical Details of the Exploit

The vulnerability arises from a misalignment between validation outcomes and matched REST handlers, allowing an attacker to validate one request while executing another. This desynchronization bypasses parameter sanitization safeguards within REST API routes.

Further investigation revealed an issue within the posts endpoint, where an author_exclude value could be unsafely sent to a database query. The AI model devised a nested batch request to circumvent method validation, leading to a pre-authentication SQL injection vulnerability.

Exploiting this SQL injection, the AI transitioned to RCE by manipulating WordPress’s in-memory post cache and oEmbed caching mechanism. By creating controlled database-backed post records, the AI forged changeset objects associated with the administrator user, temporarily assuming administrative privileges.

The attack culminated in using WordPress hooks to execute a malicious batch request, allowing the creation of a new administrator account and installation of a harmful plugin.

Response and Recommendations

Searchlight Cyber has postponed public disclosure to allow time for addressing this issue. Independent researchers, including Calif and Hacktron, have successfully replicated the exploit, and proof-of-concept code is now available on GitHub.

Administrators are advised to apply the latest WordPress security updates promptly and inspect logs for unusual requests to the /wp-json/batch/v1 endpoint. Organizations can assess their exposure using the wp2shell hosted scanner.

Strengthening cybersecurity measures by accelerating threat detection and integrating solutions like ANY.RUN with security operations centers is crucial for defending against such vulnerabilities.

Cyber Security News Tags:AI, Cybersecurity, pre-authentication, RCE vulnerability, remote code execution, security update, SQL injection, vulnerability research, WordPress, WordPress security

Post navigation

Previous Post: SonicWall Zero-Days Exploited Before Patch Release
Next Post: Attackers Exploit Windows Bind Links to Evade Detection

Related Posts

Hackers Using PuTTY for Both Lateral Movement and Data Exfiltration Hackers Using PuTTY for Both Lateral Movement and Data Exfiltration Cyber Security News
Microsoft Enhances Teams for iOS and Android Microsoft Enhances Teams for iOS and Android Cyber Security News
Famous Chollima Hackers Attacking Windows and MacOS Users With GolangGhost RAT Famous Chollima Hackers Attacking Windows and MacOS Users With GolangGhost RAT Cyber Security News
New Arkanix Stealer Attacking Users to Steal VPN Accounts, Screenshots and Wi-Fi Credentials New Arkanix Stealer Attacking Users to Steal VPN Accounts, Screenshots and Wi-Fi Credentials Cyber Security News
Firefox 140 Released With Fix for Code Execution Vulnerability Firefox 140 Released With Fix for Code Execution Vulnerability Cyber Security News
Critical Emby Server Vulnerability Let Attackers Gain Admin Access Critical Emby Server Vulnerability Let Attackers Gain Admin Access Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Defender XDR Vulnerability in Network Detection
  • HollowGraph Malware Exploits Microsoft 365 Calendar for C&C
  • SonicWall Flaws Exploited to Deploy Malware
  • Estée Lauder Faces Data Breach from Oracle Zero-Day Attack
  • Meta Awards $78,000 for Major Support Data Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Defender XDR Vulnerability in Network Detection
  • HollowGraph Malware Exploits Microsoft 365 Calendar for C&C
  • SonicWall Flaws Exploited to Deploy Malware
  • Estée Lauder Faces Data Breach from Oracle Zero-Day Attack
  • Meta Awards $78,000 for Major Support Data Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark