Security · 18h ago
AI-assisted bug hunter finds WordPress RCE, sells for $25
A security researcher used an AI tool (dubbed GPT5.6) to discover a remote code execution vulnerability in WordPress. Exploit brokers typically pay up to $500,000 for such flaws, but the researcher sold it for only $25. The finding highlights the growing role of AI in vulnerability research and the disparity in exploit market pricing.
Meridian48 take
The researcher's low sale price suggests either a naive understanding of the exploit market or a deliberate choice to undercut brokers, but the real story is how AI is democratizing — and potentially devaluing — zero-day discovery.
Read the full reporting
Exploit brokers pay $500k for WordPress RCEs. I found one with GPT5.6 and $25 →
Hacker News
wordpress-rceai-assisted-hacking