You are assuming that the white hat security researcher was the first to discover the flaw. That is a perfectly reasonable assumption, and your position is perfectly reasonable given that assumption.
GP was assuming that the white hat security researcher was not the first to discover the flaw, and that the flaw is actively being used to attack users. That is a perfectly reasonable assumption, and GP's position is perfectly reasonable given that assumption.