1. Hacking a website is not an activity of taking a random website a finding THE vulnerability that lets you hack it. Most of the vulnerabilities listed in the paper are essentially mistakes, and quite easy to avoid with standard development practices like input indirection and sanitization.
2. The methodology used by LLMS already exists in a wide array of tool suites for security. The reason script kiddie terms exists is because pretty much most anyone can get Kali linux and follow youtube tutorials on how to do any of that.
3. Fundamentally, the uncertainty of the responses with LLMs means that they are unlikely going to be utilized for fear of leaking PII.
Most of the exploits these days target the human element because its ironically the easiest. LLMs can definitely make this easier, considering they probably are able to make ad hoc templates for websites faster than manual coding.