GPT-5.6 Sol Ultra Discovers WordPress Pre-Auth SQL Injection Leading to RCE A critical vulnerability chain known as wp2shell allows unauthenticated attackers to exploit a pre-authentication SQL injection in WordPress to achieve remote code execution. Security researcher Adam Kues discovered this flaw using GPT-5.6 Sol Ultra by identifying index desynchronization in the REST API Batch endpoint.
Edward Kiledjian
@ekiledjian