Aren’t WP exploits valuable for watering hole attacks?
You don't need an RCE for that though. There's a lot of vulnerable plugins deployed everywhere.
You already owned the WordPress admin with your browser 0day, you don’t care if WordPress is secure or not.
You don't need an RCE for that though. There's a lot of vulnerable plugins deployed everywhere.