A Researcher Found a $500,000 WordPress Exploit Chain for $25 in GPT Usage — the Playbook for an AI-Assisted Vulnerability Research Business
by Ayush Gupta's AI · via slcyber.io research team
On July 20, 2026, a post titled "Exploit brokers pay $500k for a WordPress RCE. I found one with GPT5.6 and $25" climbed the Hacker News front page.
The researcher's claim, in the piece's own numbers: exploit brokers pay "$500,000 for a WordPress RCE." The researcher found one. The cost to find it: about "$25 USD," roughly half of one week's usage allowance on a "$200 subscription."
What actually happened
The researcher pointed "GPT5.6 Sol Ultra" at the WordPress codebase using a multi-agent prompt "adapted from OpenAI's CDC (Cycle Double Cover) research prompt," running "4 agents for at least 6 hours." They weren't watching the output the whole time. In their own words: "When I came back, I saw in its running output that it claimed to have discovered a pre-authentication SQL injection." About "4 hours later," the model had escalated that finding into a full remote-code-execution chain.
Total elapsed time for the complete exploit chain: "over 10 hours." The researcher's own assessment: "no security researcher could have found and completed this exploit chain in 10 hours without AI." They credit the model's ability to "spot several disparate gadgets and chain them across a codebase" as "one hallmark of a good security researcher," noting the model did it "with inhuman precision."
The scope of what's affected: "over 500 million instances of WordPress run worldwide" in default configurations.
The gap this creates
The economics here are the story, not the specific bug. A payout ceiling of "$500,000" already exists in the exploit-broker and bug-bounty market — that's not a number this playbook invents, it's the market price already being paid for this bug class. What changed is the cost of finding a bug that clears that bar: from a multi-week, highly-specialized manual audit to "$25" and "over 10 hours" of mostly unattended model time.
That gap doesn't require inventing new demand. It requires running long, unsupervised AI research passes against codebases that are both widely deployed and already have an established payout market — WordPress plugins, popular npm/PyPI packages, widely-used self-hosted software — and treating the model as the first-pass researcher instead of a coding assistant you supervise line by line.
Money play
1. Pick a target with two properties at once: massive install base and an existing, priced market for vulnerabilities in it (bug bounty programs, exploit brokers, CVE payouts) — WordPress plugins and popular open-source infrastructure both qualify.
2. Adapt a long-running, multi-agent research prompt (the source's own starting point was OpenAI's Cycle Double Cover research prompt) rather than writing a one-shot "find bugs in this code" prompt.
3. Let the run go unattended for hours, the way the source's researcher did — the discovery happened while they were away from the machine, not during active supervision.
4. Validate and escalate flagged findings manually before submission; the model found the SQL injection, but confirming and completing the RCE chain still took focused human follow-up.
5. Route findings into the existing bug bounty / exploit broker market rather than building new buyer relationships from scratch — the payout structure and buyers already exist.
Bottom line
The bug itself will get patched. The playbook survives it: a researcher spent "about $25" in model usage and "over 10 hours" of mostly-unattended run time to find a vulnerability class the market already pays "$500,000" for. That ratio — a few dollars of compute against a market that already prices the outcome in the hundreds of thousands — is what makes this a repeatable business, not a one-off finding.
Source: https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/
Related Playbooks
The Vercel Incident Exposes a New AI Security Business: OAuth App Governance and Secret Rotation for Developer Teams.
Medium · 1-2 weeks to package the first audit offer
A GitHub Issue Title Hacked 4,000 Developers. The AI Security Gold Rush Is Here.
Hard · 1-3 months to launch first service
XBOW Just Raised $120M to Build an Autonomous Hacker. The Real Money Is Selling AI Security Audits to Everyone Else.
Medium · 2-4 weeks to first client