logo

Researchers Build WordPress Exploit Using OpenAI's GPT

ID: 4f43d316-74ae-5b58-ad7f-b67b25bf586b

STIX ID: report--4f43d316-74ae-5b58-ad7f-b67b25bf586b

Feed Name: Infosecurity Magazine (News)

Threat Score
90/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

...
...

Security researchers disclosed two critical WordPress Core vulnerabilities (CVE-2026-63030: REST API route confusion leading to validation desync; CVE-2026-60137: author__not_in WP_Query SQL injection) and demonstrated an AI-crafted chained exploit (“WP2Shell”) that achieves pre-auth remote code execution on affected 6.8/6.9/7.0 installations; evidence of exploitation was reported and WordPress forced automatic updates to patch affected sites.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.