Researchers Use GPT-5.6 to Find Critical WordPress Flaw wp2shell
WordPress underpins a large share of the world’s websites, making serious flaws in the content-management system potentially far-reaching. Researchers at Searchlight Cyber used OpenAI’s GPT-5.6 Sol Ultra to analyze source code and connect elements of an exploitation chain. The experiment highlights how generative AI could sharply reduce the time, labor and cost of vulnerability research while accelerating automation for both cyber defenders and attackers.
The researchers identified the critical WordPress vulnerability, dubbed wp2shell, in about 10 hours. Cybersecurity reports published on July 22 said the flaw had moved beyond laboratory testing and was being actively exploited. Attackers were observed uploading malicious plugins, harvesting administrator credentials and gaining access to website backends, turning the AI-assisted discovery into an urgent security issue for WordPress operators.
All Coverage
3 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.