3 ms·
I work in the field and I just cannot believe anyone would pay that much for a Word Press exploit. People pay money for iOS or Android because there is valuable
by bink 2mo ago
I work in the field and I just cannot believe anyone would pay that much for a Word Press exploit. People pay money for iOS or Android because there is valuable information stored on devices running those operating systems. There's absolutely nothing of value on any Word Press site. The only possible reason I can think of is for a watering hole attack, but that would require a second exploit that would be worth far more (and they aren't).
- tedggh 2mo agoI currently work for a federal contractor including the DoD as their customer, using Wordpress as their main website. You would think there’s no sensitive information there, but some times all it takes is enough information about someone and their team to impersonate that person and gain access to an email thread, file sharing system or even an access card to a building. Never underestimate incompetence.
- soulofmischief 2mo agoAnd never underestimate the competence of others.
- kulahan 2mo agolol, a big part of security is being smart enough to never challenge the bored…
- marysol5 2mo agoSurprising amount of gov use WP as a CMS on their websites. So it's not that far off.
- madaxe_again 2mo agoThere’s a server running behind a Wordpress site. If you have RCE, you can run whatever arbitrary code you like there - mine crypto, run a botnet, all sorts of fun and profitable stuff. Hey, you can even make the site make the site’s users your unwitting hosts, too. You don’t go hack a Wordpress site, you go grab a few hundred thousand of them and do industrial scale crimes.
- JSR_FDED 2mo agoRemember the Panama papers? That was a Wordpress hack.
- grugq 2mo agoBulk reply to all the people replying. bink is correct. The people who buy exploits are governments. There is very little interest in Wordpress or indeed any target that isn't a browser or a mobile. Browsers and mobiles are the only things that are perennially useful to an intelligence agency. Those two are reliable access vectors for the vast majority of things that interest government organisations.
- mschuster91 2mo ago> There is very little interest in Wordpress I'd disagree here. Still 41% of all sites use Wordpress [1]... and that means a lot of targets, and a lot of ways to target them. Your good ole' deface/ransomware extortion scheme, leaking data supposed to be confidential (such as account lists), trusted spreaders for exploits, or the latest hit, bets on "prediction markets" that have some Wordpress site set as oracle. People are willing to screw around with airport weather stations to manipulate bets [2], it's not that much of a stretch to assume such incentives would also apply for website hackers. [1] https://www.wpzoom.com/blog/wordpress-statistics/ https://www.wpzoom.com/blog/wordpress-statistics/ [2] https://edition.cnn.com/2026/04/23/europe/france-weather-sensor-polymarket-bet-intl-latam https://edition.cnn.com/2026/04/23/europe/france-weather-sen...
- strictnein 2mo agoPlenty of underground forums sell exploits for people to do stuff like that, but you're talking $200, not a theoretical $500k. You also don't need an RCE for 99% of that.
- tptacek 2mo agoThis is an axiomatic response to an empirical argument.
- dcrazy 2mo agoAren’t WP exploits valuable for watering hole attacks?
- 2mo ago
- foco_tubi 2mo ago> There's absolutely nothing of value on any Word Press site This is just 100% an incorrect assumption. Even just an e-commerce site running Woo has troves of potentially valuable customer data. Not to mention whatever else might be on the server, or what that server is connected to...
- apercu 2mo ago>There's absolutely nothing of value on any Word Press site. I would hope not, but I’d be surprised if that were true across the millions(?) of Wordpress sites?
- technion 2mo agoCompromising a crappy wordpress site means compromising mailbox credentials. https://lolware.net/blog/2020-09-02-autodiscover-circus/ https://lolware.net/blog/2020-09-02-autodiscover-circus/