A note published by the French cybersecurity firm YesWeHack on Thursday highlights a surprising discovery: OpenAI's coding agent, Codex, was able to independently identify and exploit a critical vulnerability in WordPress that could lead to remote code execution. This revelation has sparked renewed discussions about the role of artificial intelligence in cybersecurity and bug bounty programs, where researchers are paid to find and report software flaws. The test involved Codex, which is powered by the GPT-5.6 Sol model, and demonstrated that the AI can autonomously perform complex tasks typically handled by human experts. Codex, launched by OpenAI in April 2025, is primarily a command-line tool designed to write and execute code based on natural language instructions.
For the tests, YesWeHack connected Codex to tools like Burp Suite, a widely used platform for testing web application security, and a browser controlled via the MCP protocol. This setup allowed the AI to observe and manipulate web traffic much like a human penetration tester would. The AI was able to trace vulnerabilities back to their source by analyzing the application from the outside. Additionally, researchers have shared online "reflex sheets" — pre-defined strategies for the AI — which can be customized with individual expertise to enhance its vulnerability detection capabilities.
A researcher known as HashKitten tested Codex on WordPress by challenging it to find a path to remote code execution without any authentication. The test was designed to prevent the AI from relying on pre-existing solutions or comparing its findings to known fixes. Codex identified an inconsistency in WordPress's batch processing API, turning it into an exploitable SQL injection vulnerability. After verifying the result, the researcher re-ran the AI to see if the vulnerability could be extended. Within a few hours, Codex successfully linked the flaw to other software behaviors, creating a full chain of remote code execution. The entire process cost less than $25 in computational resources, according to the study.
YesWeHack also tested Codex against two "black box" security challenges on the PortSwigger platform, where the AI was not given any information about the vulnerabilities it was supposed to find. In one test, it identified an XSS vulnerability in the way messages were managed between browser windows, despite initially searching for non-existent login pages. In another test, it bypassed a poorly secured authentication token by altering a technical parameter to mimic a fake administrator identity. Both tasks were completed efficiently, and Codex stopped at the objective without overstepping, which the researchers noted as a sign of responsible behavior.
Compared to a similar test on Anthropic's Claude Code, Codex performed more comprehensively, completing the exploits without requiring human intervention. However, YesWeHack cautioned that the test conditions were not identical, and AI systems can still make errors, get stuck on false leads, or create unstable solutions. The study emphasizes that while AI tools like Codex are powerful, human oversight remains crucial. Researchers and security experts are still the ones who define the scope of the tests and validate whether the findings are truly exploitable.
AI Coding Agent Demonstrates Autonomous Exploitation of Critical Vulnerabilities
AI-rewritten from original reportingHow it works
aicodexcybersecurityvulnerabilitywordpressbug-bounty
Original sources:
- 🇫🇷Clubic



