Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25
Summary
The article documents a complex WordPress vulnerability chain that enables pre-auth RCE via the REST batch API, combined with a SQL injection and cache/embed abuse. It details how desynchronization between validation and execution allows bypassing parameter sanitization and how an attacker can escalate to an administrator and achieve code execution, including the creation of a backdoor plugin. The piece also discusses the role of AI in discovering these techniques and the need for defenders to upgrade WordPress and monitor for similar multi stage exploits.