Exploit brokers shell out $500,000 for WordPress RCEs; researcher discovers one using GPT‑5.6 for $25

Exploit brokers have a market for WordPress remote code execution (RCE) vulnerabilities. They are reportedly willing to pay up to $500,000 for such

Exploit brokers have a market for WordPress remote code execution (RCE) vulnerabilities. They are reportedly willing to pay up to $500,000 for such exploits. A researcher reported finding a WordPress RCE using the AI model GPT‑5.6. The discovery cost only $25 in resources. This contrast highlights the disparity between broker payouts and research costs. The finding suggests AI tools can aid low‑cost vulnerability discovery. Brokers continue to seek high‑value exploits for resale on underground markets. Observers will watch whether AI‑driven methods lower overall exploit prices.