Ten Hours and $25: How AI Reshaped WordPress Vulnerability Timeline
Key Takeaways
- ▸OpenAI's GPT-5.6 Sol Ultra discovered a critical WordPress SQL injection vulnerability in 10 hours for ~$25, demonstrating the speed and cost-efficiency of AI-driven security research.
- ▸The typical 'defender advantage' window has collapsed: attackers weaponized the patch in 90 minutes, eliminating the traditional days or weeks before active exploitation.
- ▸WordPress security reports have surged 15-fold to 450 in July, reflecting AI-accelerated vulnerability discovery across the ecosystem.
Summary
OpenAI's GPT-5.6 Sol Ultra, operated by Searchlight Cyber, discovered a critical WordPress vulnerability—a SQL injection chained to remote code execution—in just 10 hours at a cost of approximately $25. WordPress released security patches to address this and other vulnerabilities on July 17 (7.0.2) and August 6 (7.0.3), but the compressed timeline for exploitation highlights a fundamental shift in the security landscape. Attackers began exploitation attempts just 90 minutes after the 7.0.2 patch was released, with Patchstack detecting over 65,000 attempts from more than 1,500 addresses in the following days.
The incident marks a turning point in AI-driven security research. WordPress security reports through HackerOne surged from dozens per month (consistent for nine years) to 450 in July alone, suggesting widespread adoption of AI for vulnerability discovery. Patchstack notes that the researcher's traditional role has shifted: AI models now autonomously find flaws and carry them to exploitation, with human researchers primarily responsible for filing reports. This acceleration is not limited to WordPress—other critical vulnerabilities in the August release were discovered by pwn.ai (autonomous penetration testing) and Anthropic, underscoring a broader trend.
- The vulnerability lifecycle has fundamentally changed—AI systems now autonomously find vulnerabilities and carry them to exploitation, reducing human researchers to reporting duties rather than discovery.
Editorial Opinion
The real story here is the compression of the entire timeline. When a model can find working remote code execution in ten hours for the cost of lunch, and attackers can operationalize a patch within 90 minutes, the traditional assumptions about defender response windows become obsolete. This isn't a failure of WordPress—it's a systemic shift where AI-driven research has become the bottleneck, and hosting providers are increasingly the only line of defense between discovery and widespread compromise. The security industry must fundamentally recalibrate its assumptions about the defender's advantage.



