logoalt Hacker News

ahartmetzyesterday at 9:08 AM4 repliesview on HN

The surprising (and possibly untrue) thing is the high price of canned vulnerabilities. WordPress is known as the remote root shell with a blogging feature.


Replies

denysvitaliyesterday at 10:42 AM

I still don't understand why, for a blog, a static page isn't enough - especially since most of the WordPress issues are "solved" by adding caching.

I do understand it from an user perspective (it's easier to tell the average user to drag and drop rather than committing to a GitHub repo and letting hugo build the website), but from a security standpoint WordPress is really just waiting for a vulnerability (either in the core or on the thousands of plugins) in order to unlock its RCE-as-a-service functionality.

show 6 replies
gorszonyesterday at 9:13 AM

Propably untrue, the only way to know is to do threat intelligence, and inflitrate those telegram groups where these brokers operate, I doubt the writer of the article did that. Maybe he conflated any vulnerability with a 0-day one?

show 1 reply
slimyesterday at 11:57 AM

  WordPress is one of the most hardened targets of all time
that obsolete code did not change for decades. all the bugs have been discovered and patched
lyu07282yesterday at 9:25 AM

some statistics point to almost 50% of all websites on the internet running on Wordpress, $500k for an undisclosed 0day unauthenticated RCE doesn't seem so unrealistic to me

show 1 reply