Comment by grugq

1 day ago

Bulk reply to all the people replying.

bink is correct. The people who buy exploits are governments. There is very little interest in Wordpress or indeed any target that isn't a browser or a mobile. Browsers and mobiles are the only things that are perennially useful to an intelligence agency. Those two are reliable access vectors for the vast majority of things that interest government organisations.

Are they only buying browser RCEs or are they also interested in RCEs deliverable via browser?

ex: Target hits website -> site delivers RCE for some software that is on the target's system

Aren’t WP exploits valuable for watering hole attacks?

  • You don't need an RCE for that though. There's a lot of vulnerable plugins deployed everywhere.

    • Ok, but an RCE in WP Core still seems pretty dang valuable, especially if you want to hit non-commercial websites that are less likely to have as many plugins installed?

  • You already owned the WordPress admin with your browser 0day, you don’t care if WordPress is secure or not.

> There is very little interest in Wordpress

I'd disagree here. Still 41% of all sites use Wordpress [1]... and that means a lot of targets, and a lot of ways to target them. Your good ole' deface/ransomware extortion scheme, leaking data supposed to be confidential (such as account lists), trusted spreaders for exploits, or the latest hit, bets on "prediction markets" that have some Wordpress site set as oracle. People are willing to screw around with airport weather stations to manipulate bets [2], it's not that much of a stretch to assume such incentives would also apply for website hackers.

[1] https://www.wpzoom.com/blog/wordpress-statistics/

[2] https://edition.cnn.com/2026/04/23/europe/france-weather-sen...

  • Plenty of underground forums sell exploits for people to do stuff like that, but you're talking $200, not a theoretical $500k.

    You also don't need an RCE for 99% of that.