A security researcher used GPT-5.6 to discover a pre-authentication SQL injection vulnerability in WordPress, which can be escalated to a remote code execution (RCE) exploit. The vulnerability was found using a carefully crafted prompt and the researcher was able to verify the exploit on a test instance. The researcher notes that the vulnerability is significant due to the widespread use of WordPress. The exploit was discovered with a relatively low cost of $25.