A significant vulnerability in WordPress has been discovered, with exploit brokers offering up to $500,000 for remote code execution (RCE) exploits. Notably, a researcher was able to identify a WordPress RCE using GPT5.6, a version of the Generative Pre-trained Transformer, and a budget of just $25. This stark contrast highlights the accessibility of vulnerability discovery in popular content management systems. The researcher's findings demonstrate that substantial rewards for exploits do not necessarily correlate with the difficulty or expense of discovering them. Specifically, the use of GPT5.6 in this context showcases the potential for AI-powered tools to aid in vulnerability detection, potentially leveling the playing field for security researchers1. This matters to security practitioners because it underscores the importance of prioritizing WordPress security updates and monitoring, given the relatively low barrier to entry for would-be exploiters.