news.volyx.in

I found a WordPress RCEs with GPT5.6 and $25 (slcyber.io)

391 points by infosecau · 38 days ago · 214 comments on HN

Article summary

A security researcher used GPT-5.6 to discover a pre-authentication SQL injection vulnerability in WordPress, which can be escalated to a remote code execution (RCE) exploit. The vulnerability was found using a carefully crafted prompt and the researcher was able to verify the exploit on a test instance. The researcher notes that the vulnerability is significant due to the widespread use of WordPress. The exploit was discovered with a relatively low cost of $25.

Main themes

  • WordPress vulnerability
  • LLM-assisted exploit discovery
  • Cybersecurity risks
  • Exploit brokers
  • Software security
  • AI-powered hacking

What commenters say

  • The use of LLMs like GPT-5.6 can significantly lower the cost and increase the efficiency of discovering vulnerabilities in software like WordPress.
  • The market for exploits may adjust to the increased supply of vulnerabilities discovered by LLMs, potentially reducing their value.
  • WordPress is a popular target for hackers due to its widespread use and the ease of exploitation of its vulnerabilities.
  • The WordPress codebase is criticized for being outdated and poorly maintained, making it vulnerable to exploits.
  • The use of LLMs for exploit discovery raises concerns about the potential for malicious actors to use these tools for hacking.
  • The value of exploits like the one discovered in WordPress may be lower than reported, and the market for exploits may not be as lucrative as claimed.
  • The discovery of vulnerabilities in WordPress highlights the need for better security practices and more secure coding standards.
  • The use of AI-powered tools like GPT-5.6 for cybersecurity research is a double-edged sword, offering both benefits and risks.