I found a WordPress RCEs with GPT5.6 and $25 (slcyber.io)
388 points by infosecau a day ago
Zsfe510asG 19 hours ago
There is no evidence that $500k has been paid or would be paid for an exploit like this one.
Given that the article says that prompts are modified like they are holy scripture, perhaps sell the prompt for $500k.
The author works for https://www.assetnote.io/ , which has AI products for automated scanning.
kuroguro 19 hours ago
Likely referencing https://www.crowdfense.com/exploit-acquisition-program/
Zerodium used to offer up to 300k in 2021 https://www.securityweek.com/sites/default/files/images/Zero...
These brokers usually don't pay the bulk sum - they sell access to nation actors and you get payed out over time as long as the bug is not patched to discourage reselling and burning it. I doubt anyone would confirm if they got the full payment or not for something similar.
bink 18 hours ago
I work in the field and I just cannot believe anyone would pay that much for a Word Press exploit. People pay money for iOS or Android because there is valuable information stored on devices running those operating systems. There's absolutely nothing of value on any Word Press site. The only possible reason I can think of is for a watering hole attack, but that would require a second exploit that would be worth far more (and they aren't).
tedggh 17 hours ago
grugq 13 hours ago
technion 9 hours ago
JSR_FDED 13 hours ago
marysol5 17 hours ago
foco_tubi 13 hours ago
apercu 11 hours ago
madaxe_again 15 hours ago
Hizonner 18 hours ago
Why would anybody trust criminals to pay them over time?
idiotsecant 18 hours ago
monster_truck 15 hours ago
What do you think the venn diagram looks like for people willing and able to find things like that prior to LLMs and also sell them to a broker, and are also stupid enough to flaunt a massive flashing "arrest me!!!" sign
Closest you're going to get is something like those kids in florida who just got wrapped for putting malware into steam games and draining peoples accounts. They were going to get caught anyways but it would have taken a lot longer to build a case against them if they weren't flaunting it on socials
nickff 12 hours ago
Is this comment pure speculation, or do you have knowledge (or anecdotal evidence) of a similar exploit being sold for $500k?
trollbridge 16 hours ago
"People paid $5,000 for a Macintosh computer when they were new. I found one at a yard sale for $25."
sgerenser 5 hours ago
Pre-1990s Macs (Mac Plus, SE, etc.) in good condition are actually worth a decent amount nowadays as collectors items. Not $5000, but quite a bit more than $25.
grugq 14 hours ago
this is the most accurate summary.
trollbridge 12 hours ago
dang 6 hours ago
Ok, we've taken $500k out of the title above.
nativeit 17 hours ago
> modified like they are holy scripture
So never modified at all, even if plainly contradictory and/or ethically and morally compromised?
functionmouse 19 hours ago
sloptimists are liars
not big surprise
progbits 21 hours ago
https://github.com/WordPress/WordPress/commit/3a640e1c5e39aa...
String concatenation SQL injection in the year 2026.
sunaookami 21 hours ago
Oh it's even worse: https://developer.wordpress.org/plugins/creating-tables-with...
>Rather than executing an SQL query directly, we’ll use the dbDelta function
>Note that the dbDelta function is rather picky, however. For instance:
>You must put each field on its own line in your SQL statement.
>You must have two spaces between the words PRIMARY KEY and the definition of your primary key.
>You must use the key word KEY rather than its synonym INDEX and you must include at least one KEY.
>KEY must be followed by a SINGLE SPACE then the key name then a space then open parenthesis with the field name then a closed parenthesis.
>You must not use any apostrophes or backticks around field names.
>Field types must be all lowercase.
>SQL keywords, like CREATE TABLE and UPDATE, must be uppercase.
>You must specify the length of all fields that accept a length parameter. int(11), for example.
duped 15 hours ago
Sometimes when you write documentation for APIs you realize something is terribly designed. That should have happened here.
madaxe_again 15 hours ago
I like that you chose ten examples.
>> s/you must/thou shalt/g
9dev 21 hours ago
The WordPress codebase is a disgrace. PHP is a beautiful language by now, but they absolutely butcher it and refuse to do anything about that.
CM30 20 hours ago
It's just because they don't want to break anything in existing sites, sorta like how Microsoft doesn't generally want to break programs on Windows. So, changes are fairly incremental, and the quality is about what you'd expect from a piece of software that's decades old with no plan for what happens if it got this far.
But what do you do in that situation? If they change the structure too much, then either they make it impossible to upgrade an existing site, or potentially break a whole bunch of things said sites depend on (mostly themes and plugins). And that ease of upgrading is likely what stops a lot of people just migrating away to other solutions.
9dev 20 hours ago
liveoneggs 19 hours ago
antonymoose 11 hours ago
tonyedgecombe 19 hours ago
bilekas 20 hours ago
I'm convinced it's by design so that the community that build little businesses around wordpress still stay in the eco system. A client needs new functionality? That's be a week of work because god help anyone who wants to look into themselves.
WordPress is actively degrading the security and quality of the web I general. Has been for many many years.
bayindirh 20 hours ago
The great irony is they still sport their "Code is Poetry" mantra on their website [0].
If code is poetry, Wordpress is a new genre of it, probably?
ralferoo 20 hours ago
chrismorgan 17 hours ago
tiborsaas 18 hours ago
Yokolos 20 hours ago
bell-cot 20 hours ago
evantbyrne 19 hours ago
Everything I've used from Automattic has felt that way. If you ever want to torture an engineer, just make them change the layout of WooCommerce checkout.
asimovDev 21 hours ago
As a junior I am glad I happened to start working with PHP on version 7. I had some peeks at our legacy PHP5 stuff (all killed now thankfully) and it looked very different. I am sure it would suck to work with.
thejosh 21 hours ago
geek_at 21 hours ago
it would help if they used strict types and modern standards but as you say the wordpress codebase is beyond dated and held together with duckt tape
khalic 21 hours ago
I remember multiple projects giving up on rewriting it. Maybe a machine with endless patience could do it?
hparadiz 20 hours ago
pwillia7 18 hours ago
tbf literally all my php hate comes directly from WP
mono442 20 hours ago
PHP is a proof that you don't need elegant or good technical solutions to be successful. You can literally pile up slop together and still be successful.
9dev 20 hours ago
marysol5 17 hours ago
hparadiz 20 hours ago
It was like that in the old days too. Seriously who makes a postmeta table and goes "yea let's just throw everything in here. Indexes? Meh."
I cringe everytime.
cute_boi 16 hours ago
I don't think PHP is a beautiful language. If it was Laravel wouldn't need to rewrite every function from standard library. And, I see no reason to use it compared to Typescript.
9dev 12 hours ago
sofixa 16 hours ago
dinkelberg 21 hours ago
What an awful fix. Does WordPress seriously still use basic string concatenation (edit: and sprintf) to build SQL queries?
Yokohiii 20 hours ago
To construct dynamic sql queries to have to string concatenate at least some parts, .
User data should of course be passed via prepared statements.
codedokode 16 hours ago
formerly_proven 19 hours ago
reddalo 21 hours ago
WordPress source code is a mess. They should re-write it from scratch using modern technologies, or even a framework like Laravel.
mewpmewp2 20 hours ago
mapmeld 20 hours ago
pluc 19 hours ago
sourcecodeplz 20 hours ago
dncornholio 18 hours ago
SpikedCola 16 hours ago
Ahhh very interesting! Thanks for pointing this out, I saw an attack against one of our sites this weekend using this exploit.
> data: {'requests': [{'method': 'POST', 'path': 'http://:'}, {'body': {'requests': [{'method': 'GET', 'path': 'http://:'}, {'method': 'GET', 'path': '/wp/v2/widgets?author_exclude=1%29+AND+1%3D0+UNION+ALL+SELECT+0%2C1%2C0x323...
m00dy 20 hours ago
>>Principal Software Engineer @ Bluehost. WordPress Core Committer. Baseball fan.
hmm yes, definitely. You are the principal.
hmokiguess 19 hours ago
I am so done with FOMO writing. Sure man, you found one with $25. With $25 plus your entire industry domain specific knowledge of where to look, of how to probe, of what else you may have accumulated and collected over the years of working within this industry. Let's stop with the gambling narrative and the illusion that we are all missing out.
w4yai 18 hours ago
I agree. This is so toxic! It feels like the Instagram of articles. "Look how my life is great" - yeah sure, you're posting only happy moments.
Not only $25 is not accounting the years of experience, but also all the failed attempts.
paodealho 13 hours ago
Should also note the math done on the token costs. $25 of subsidized tokens because he's on a subscription plan.
recitedropper 16 hours ago
I can't agree with this more. May cooler, more compassionate minds prevail.
deaton 15 hours ago
And nobody would post "I did it for free!" if they had done it themselves, but somehow spending $25 on tokens changes how we're supposed to look at it
ahartmetz a day ago
The surprising (and possibly untrue) thing is the high price of canned vulnerabilities. WordPress is known as the remote root shell with a blogging feature.
denysvitali 20 hours ago
I still don't understand why, for a blog, a static page isn't enough - especially since most of the WordPress issues are "solved" by adding caching.
I do understand it from an user perspective (it's easier to tell the average user to drag and drop rather than committing to a GitHub repo and letting hugo build the website), but from a security standpoint WordPress is really just waiting for a vulnerability (either in the core or on the thousands of plugins) in order to unlock its RCE-as-a-service functionality.
muvlon 18 hours ago
In many deployments, Wordpress started out as just a blog that is easy to edit right from the web browser, but then grew into way more. Most commonly, people end up retrofitting all kinds of e-commerce features onto it, and that's how you really get into the whole plugin mess. At that point, for better or worse, the Wordpress instance is serving important business needs that are not addressed by a static page.
marysol5 17 hours ago
CM30 20 hours ago
People like having a WYSIWYG editor, being able to update their posts in the browser, having comments and being able to use plugins. They're also not particularly skilled with the terminal/commands, and a lot of hosts provide a one-click install setup for scripts like WordPress.
mewpmewp2 20 hours ago
Like you said. It is a product for people who are not technical and don't code. A product that you would have to use git for, wouldn't be used by the 90 percent in the first place. And there are such products. There is a reason WordPress is the most popular platform. Most people are not technical.
And people like to be able to extend from Blogs to various other non static features which WordPress allows for.
thenthenthen 18 hours ago
acomjean 19 hours ago
The non-profit I help with moved to Wordpress so people can edit the site without having to use git. (We have a lot more editors now)..
1123581321 19 hours ago
- Anyone can edit it
- Less training; org probably has someone who’s used Wordpress before. (Yes, training. You must deal with the reality of the typical user.)
- In the developing group or agency, anyone can work on the theme if you install a theme builder. An agency can put a cheaper content marketer or designer on it, rather than a developer.
pwillia7 18 hours ago
WPE tried to make Faust.js a thing so you could use WP CMS but generate a modern static site but I don't think it really took off much
gorszon a day ago
Propably untrue, the only way to know is to do threat intelligence, and inflitrate those telegram groups where these brokers operate, I doubt the writer of the article did that. Maybe he conflated any vulnerability with a 0-day one?
blauditore 21 hours ago
...or was just looking for a clickbait title.
Surely someone once offered a vulnerability for 500k somewhere, but that doesn't mean someone bought it.
slim 19 hours ago
WordPress is one of the most hardened targets of all time
that obsolete code did not change for decades. all the bugs have been discovered and patchedlyu07282 21 hours ago
some statistics point to almost 50% of all websites on the internet running on Wordpress, $500k for an undisclosed 0day unauthenticated RCE doesn't seem so unrealistic to me
addedlovely 20 hours ago
I've got it at 38.32%. I'm looking at the 'front-door' of the web, active sites, no subdomains, from Crux user experience data.
Will be publishing a report on www.theweb.report soon - if you're interested.
That's a seed of about 13 million domains - pretty sure WordPress would be dominating the even longer tail.
( Also worth noting it's sooo easy to detect a site is WordPress, it screams it across every signal we gather, where-as some sites are just well made and have limited information leaks ).
raesene9 21 hours ago
Interesting write-up and I do think LLM assisted/powered exploit disclosure is a real concern (I've been able to get models to create container breakouts from Linux LPEs relatively quickly).
One thing I'm surprised about is that GPT-5.6 didn't block that prompt due to guardrails. My experience is that GPT-5.5 and up does not like offensive security work (similar to Opus 4.7+/Fable).
I didn't notice it but I'd assume that the authors have some level of cyber approvals from OpenAI to relax the guardrails a bit.
Santas 21 hours ago
This might help https://chatgpt.com/cyber ease the guardrails a bit.
eru 20 hours ago
Thanks! I wonder if Claude has something similar?
NiekvdMaas 20 hours ago
lillesvin 19 hours ago
I feel like I've seen plenty of non-AI, pre-2020 SAST tools catch SQLis like the one mentioned here, and if nothing else, then a code review ought to catch it. Is WordPress not using code reviews and/or SAST?
f311a 14 hours ago
They would not catch it, it requires combining multiple vulns.
secretslol 14 hours ago
One of my websites was hacked with this, luckily not one with any users at all.
They did this:
- Two admin accounts in the database.
- plugin dir: wp-content/plugins/wp-core with remote command-execution web shell wp-core-[12 random chars].php
- firewall.php backdoor in mu-plugins dir with admin on GET ?sergei
- cache-seo-helper.php backdoor
- fixer.php which renames the wordpress version number to one which is patched.
I have decided to give up on Wordpress.
lexicality 20 hours ago
The author lost me at the last bit where they started using weird names for the posts. Why would you make one ID O and the other ID 0? Why single letters and not EMBED_01? Why seemingly random letters instead of ABCDEF? Does OCPDST stand for something?
moebrowne 20 hours ago
They are placeholders, their meanings are spelled out in the post:
O: publish/oembed_cache, empty content, stale timestamp with parent C
C: future/customize_changeset, changeset JSON with parent C
P: draft/page, with parent D
D: parse/request with itself as its parent
S: publish/post, for providing embed data
T: publish/post, containing the outer embedlexicality 13 hours ago
That doesn't actually answer any of my questions though. Why is `S` the placeholder for "post"? T for T'outer?
ameliaquining 5 hours ago
I might be missing something, so perhaps someone can explain: Why are the steps in the middle of the exploit chain necessary? The writeup describes getting a SQL injection, then going from there to cache poisoning to exploiting various logic bugs, to eventually creating an admin account (and WordPress grants RCE to admin accounts by design). But if you have a SQL injection, why can't you use that to just create an admin account directly, by inserting it into the users table?
cromka 21 hours ago
This assumes those who'd pay $500k don't have the skill to use GTP5.6 for the same purpose themselves?
elmer2 18 hours ago
Then why didn't we see the same writeup earlier? If you look through the writeup, you still need the skills to go through what the LLM gives you and actually create a valid proof of concept.
I've been using LLMs to find security vulnerabilities and there is no way I can just submit what I found and call it a day (many try).
cheschire 21 hours ago
You read articles regularly about how X authority is provided cloud LLM history and uses it as evidence to prosecute a defendant.
Yet you think professional criminals are too stupid to launder their activities through an unscrupulous yet legal intermediary?
khurs 21 hours ago
People who make the money are not necessarily the people who can write the best code.
Elon Musk didn't write code for a rocket, he hired people who could.
ifdefdebug 21 hours ago
> Is GPT5.6 Sol Superhuman?
This is not a simple y/n question. Computers have been superhuman at playing chess for decades now. Reading this article, I guess they are superhuman at understanding code now as well.
chrisjj 21 hours ago
> Computers have been superhuman at playing chess for decades now.
And at doing arithmetic for even longer /i
dzonga 19 hours ago
wordpress is so shitty - though it runs the majority of the web.
people think PHP is shitty cz of Wordpress.
at a certain point in time - people need to move to better ecosystems painful as that may be.
f311a 14 hours ago
Historically, a lot vulnerabilities in PHP projects were because of PHP itself. Things like register_globals, remote includes/reads using functions that supposed to read local data and so on.
barbazoo 12 hours ago
I'd expect the amount of money paid for exploits to go down then. It's inefficient to pay >$25 for an exploit that took $25 to make.
cadamsdotcom 20 hours ago
That was an incredible writeup! Chapeau to the author - thanks for taking the time to do a writeup.
When Anthropic claimed Mythos chained 4 or 5 bugs to achieve sandbox escape and found bugs in core software, it sounded like bs. But here we are 2 months later seeing what they meant.
Cybersecurity was always a hard sell; security flaws were invisible - by contrast a fence with a hole is visible to everyone - anyone can ignore the locked gate and walk through the fence hole. With cybersecurity a hole in the fence may go unnoticed for years, maybe forever.
LLMs level the field. We will all benefit from more secure systems, a few people will get a lot of egg on their faces, and it will end the malpractice of underinvesting in software security to get a product out the door.
alienbaby 19 hours ago
| We will all benefit from more secure systems
the people that can afford it, sure.
s3p 19 hours ago
Can some people not afford open source software?
vavkamil a day ago
This one is both awesome and scary. We are living in a black mirror episode, where one well-crafted LLM prompt can get you $500k or the ability to hack into 500M websites :)
wongarsu 21 hours ago
The market will quickly adjust to the point where spending $50 on tokens will on average give you a vulnerability valued at $50. Maybe $100 to account for your edge in having a better prompt and the risk of prison time you take in selling the exploit
In fact that may well be true today. OP didn't try to sell it to discover the true price the market is willing to pay. And we all know that "somebody paid $$$ for something similar in the past" is no guarantee that somebody else is willing to pay any significant sum for your thing today. If it was, startups would be a lot easier
hoppp 21 hours ago
I don't think OP got $500k , it's only clickbait in the title.
Philip-J-Fry 21 hours ago
One LLM prompt can't get you $500K. Why would someone spend $500k instead of just prompting themselves?
inigyou 21 hours ago
Because they don't know you can
muldvarp 15 hours ago
cbg0 21 hours ago
Don't get all starry-eyed, the people owning those sites also have access to LLMs, so both the hacks and paydays are rare.
throwitaway222 14 hours ago
Seems like exploit brokers can just buy a codex license and put the 500k towards finding all bugs in all software for the price of one bug
_superposition_ 20 hours ago
The cost of business nowadays? At what point does it become apparent that in today's world software needs continuous pen testing and scanning? If you don't your attackers will.
alienbaby 19 hours ago
| in today's world software needs continuous pen testing and scanning
points to a bigger problem perhaps; software design, construction and distribution is fundamentally flawed.
tantalor 19 hours ago
Is this real? Or did they concoct this vulnerability just to write a blog post?
I'm not seeing any mention where they report this to WP or the patch.
testplzignore 18 hours ago
r1ch 19 hours ago
Does Sol allow this kind of research by default or is this a "look at me I'm on the cyber research allowlist" post?
_joel 18 hours ago
The "pro's buy out a company that has a massive add-on install base with the most non-technical users.
mixtureoftakes 21 hours ago
What was the harness used? And yeah surprised about such prompts not being downright blocked, even with the cybersafety verification"
aussieguy1234 a day ago
So they spent the $25. But the real question here is did they get the $500K?
az226 13 hours ago
Unquestionably they did not.
Their listed pricing was up to $50k.
https://cyber-peace.org/wp-content/uploads/2017/09/ZERODIUM-...
And that was before LLMs could produce these at volume.
The demand (dollars) does not go up commensurately with the supply. So today maybe $500 or a few thousand. Maybe not even that.
elmer2 18 hours ago
Probably not. The Wordpress Bug Bounty program pays very little. Exploit brokers will pay 500K, but we wouldn't be seeing it here if it was sold.
preetham_rangu a day ago
Nice balance between practicality and ambition. Curious how it holds up with real-world scale.
jorisw 21 hours ago
RCE — Remote code execution
sashank_1509 15 hours ago
Thanks
CodeCompost 21 hours ago
I like the idea of not crediting the person who posted the bug but to the LLM that found it. People who find exploits using LLMs should never get a reward or credit.
pelagicAustral 21 hours ago
So people coding with LLMs shouldn't get paid then, right?
grey-area 21 hours ago
That is in fact the end goal of CEOs pushing LLM use yes. Not possible right now, but if it were they would absolutely take that option.
jorisw 21 hours ago
muldvarp 15 hours ago
Do you assume that five years from now you'll get paid for coding with LLMs?
bakugo 21 hours ago
Correct.
chrisjj 21 hours ago
They should get paid by the LMM only.
Levitz 20 hours ago
It baffles me how this can be said without concern for first order consequences.
nubg 21 hours ago
I agree! We should go all the way though and credit the authors of the data the LLM was trained on. People who just run LLMs training scripts should never get a reward or credit.
defmacr0 21 hours ago
I take credit given all my infosec-related reddit posts they used for training.
perarneng 18 hours ago
How do you find exploits without risking someone seeing your attempt and reporting you as a hacker? do you register first somewhere?
kamranjon 18 hours ago
You can run Wordpress locally in your own sandbox to test these vulnerabilities, you don’t have to break any laws.
j45 12 hours ago
I wonder if there could be a crowdfunding to harden Wordpress with the leading models, or some who might have access to something like a Mythos level.
stared 20 hours ago
On another note - who needs WordPress in the age of Astro and LLMs?
I mean, it's not a taunt, but a serious question - do people keep WordPress because it used to be the easiest solution to set up years ago, or are there still clear use cases where one can argue it's the best solution?
justanotherunit 19 hours ago
I have not yet seen an alternative for Wordpress + woocommerce for a simple e-commerce site that is not more expensive. I am open for alternatives tho if anyone knows any
crummy 20 hours ago
does Astro do WYSWIYG?
IshKebab a day ago
Presumably they don't pay $500k anymore...
rvz 21 hours ago
Just like that, the 0-day black market is experiencing a mini black Monday.
yellow_lead 21 hours ago
Can RCEs like this still be sold to exploit brokers like Zerodium? If so, how? Asking for a friend
titularcomment 16 hours ago
lol. Simple case of if you have to ask, you probably shouldn't.