AI-discovered $25 exploit threatens 500 million WordPress video news sites
Security researchers have identified the 'WP2Shell' remote code execution (RCE) vulnerability chain in WordPress Core, which was discovered using AI at a cost of only $25. WordPress has released emergency security patches (versions 7.0.2 and 6.9.5) to address the flaw, which currently affects millions of websites.
Key Takeaways
- Vulnerability chain WP2Shell combines CVE-2026-63030 and CVE-2026-60137 to bypass authentication and execute code via SQL injection.
- Discovery process took only 10 hours using automated AI agents, representing a 20,000-fold cost reduction compared to traditional exploit broker markets.
- WordPress issued emergency security patches versions 7.0.2 and 6.9.5 and initiated rare forced automatic updates for millions of users.
- Assetnote researcher Adam Kues confirmed the AI built a multi-stage exploit that poisons caches and uploads hidden malicious plugins.
Why It Matters
The speed and negligible cost of this AI-driven discovery fundamentally alter the threat landscape for media companies relying on WordPress for content distribution. While WordPress issued immediate patches, the incident proves that legacy codebases are now transparent to low-cost LLM analysis, making manual security audits insufficient. In the streaming ecosystem, where CMS-integrated video players and ad-servers are critical revenue engines, a hijacked server can lead to widespread malware distribution or large-scale viewer data exfiltration. Operators should watch for a surge in CVEs targeting established PHP-based architectures as bad actors adopt similar automated pentesting tools.
Additional Context
The WP2Shell incident arrives as the Cybersecurity and Infrastructure Security Agency (CISA) intensifies its 'Secure by Design' initiative, which explicitly calls for software vendors to eliminate entire classes of vulnerabilities like SQL injection before products hit the market. Per a CISA report from June 2026, the agency noted a 40% increase in critical vulnerabilities found in open-source components over the previous year, largely driven by automated scanning tools. This trend has placed immense pressure on the WordPress foundation to modernize its 23-year-old architectural framework, which many engineers argue is increasingly incompatible with modern security standards. Simultaneously, the cost of zero-day exploits has begun to fluctuate wildly due to AI's influence. While Crowdfense and Zerodium historically offered up to $500,000 for WordPress RCE chains, the proliferation of LLM-aided discovery is expected to saturate the market with similar bugs. Per Wired in July 2026, security analysts warned that the 'barrier to entry for sophisticated cyberespionage' has effectively vanished, as models like GPT 5.6 can now perform the labor of a senior security researcher for the price of a mid-sized team's lunch. Major cloud providers serving the media industry, including AWS and Google Cloud, have responded by integrating 'AI-shield' layers at the WAF (Web Application Firewall) level. According to a July 2026 technical brief from Google Cloud, these systems are designed to detect the specific multi-stage 'chaining' logic used by automated AI agents like those employed by Assetnote. For streaming platforms, this shift emphasizes that security is moving away from reactive patching toward real-time, AI-monitored traffic analysis to catch exploits that move faster than human patch cycles.
Read full article at tvnewscheck.com
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source