← Back to context Comment by dcrazy 1 day ago Aren’t WP exploits valuable for watering hole attacks? 3 comments dcrazy Reply strictnein 1 day ago You don't need an RCE for that though. There's a lot of vulnerable plugins deployed everywhere. dcrazy 1 day ago Ok, but an RCE in WP Core still seems pretty dang valuable, especially if you want to hit non-commercial websites that are less likely to have as many plugins installed? illliillll 1 day ago You already owned the WordPress admin with your browser 0day, you don’t care if WordPress is secure or not.
strictnein 1 day ago You don't need an RCE for that though. There's a lot of vulnerable plugins deployed everywhere. dcrazy 1 day ago Ok, but an RCE in WP Core still seems pretty dang valuable, especially if you want to hit non-commercial websites that are less likely to have as many plugins installed?
dcrazy 1 day ago Ok, but an RCE in WP Core still seems pretty dang valuable, especially if you want to hit non-commercial websites that are less likely to have as many plugins installed?
illliillll 1 day ago You already owned the WordPress admin with your browser 0day, you don’t care if WordPress is secure or not.
You don't need an RCE for that though. There's a lot of vulnerable plugins deployed everywhere.
Ok, but an RCE in WP Core still seems pretty dang valuable, especially if you want to hit non-commercial websites that are less likely to have as many plugins installed?
You already owned the WordPress admin with your browser 0day, you don’t care if WordPress is secure or not.