Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

59% Positive

Analyzed from 3968 words in the discussion.

Trending Topics

#wordpress#php#don#code#https#site#exploit#pay#more#llms

Discussion (209 Comments)Read Original on HackerNews

Zsfe510asGabout 15 hours ago
There is no evidence that $500k has been paid or would be paid for an exploit like this one.

Given that the article says that prompts are modified like they are holy scripture, perhaps sell the prompt for $500k.

The author works for https://www.assetnote.io/ , which has AI products for automated scanning.

kuroguroabout 14 hours ago
Likely referencing https://www.crowdfense.com/exploit-acquisition-program/

Zerodium used to offer up to 300k in 2021 https://www.securityweek.com/sites/default/files/images/Zero...

These brokers usually don't pay the bulk sum - they sell access to nation actors and you get payed out over time as long as the bug is not patched to discourage reselling and burning it. I doubt anyone would confirm if they got the full payment or not for something similar.

binkabout 14 hours ago
I work in the field and I just cannot believe anyone would pay that much for a Word Press exploit. People pay money for iOS or Android because there is valuable information stored on devices running those operating systems. There's absolutely nothing of value on any Word Press site. The only possible reason I can think of is for a watering hole attack, but that would require a second exploit that would be worth far more (and they aren't).
tedgghabout 13 hours ago
I currently work for a federal contractor including the DoD as their customer, using Wordpress as their main website. You would think there’s no sensitive information there, but some times all it takes is enough information about someone and their team to impersonate that person and gain access to an email thread, file sharing system or even an access card to a building. Never underestimate incompetence.
grugqabout 8 hours ago
Bulk reply to all the people replying.

bink is correct. The people who buy exploits are governments. There is very little interest in Wordpress or indeed any target that isn't a browser or a mobile. Browsers and mobiles are the only things that are perennially useful to an intelligence agency. Those two are reliable access vectors for the vast majority of things that interest government organisations.

technionabout 5 hours ago
Compromising a crappy wordpress site means compromising mailbox credentials.

https://lolware.net/blog/2020-09-02-autodiscover-circus/

JSR_FDEDabout 9 hours ago
Remember the Panama papers? That was a Wordpress hack.
marysol5about 12 hours ago
Surprising amount of gov use WP as a CMS on their websites. So it's not that far off.
foco_tubiabout 8 hours ago
> There's absolutely nothing of value on any Word Press site

This is just 100% an incorrect assumption. Even just an e-commerce site running Woo has troves of potentially valuable customer data. Not to mention whatever else might be on the server, or what that server is connected to...

apercuabout 7 hours ago
>There's absolutely nothing of value on any Word Press site.

I would hope not, but I’d be surprised if that were true across the millions(?) of Wordpress sites?

madaxe_againabout 11 hours ago
There’s a server running behind a Wordpress site. If you have RCE, you can run whatever arbitrary code you like there - mine crypto, run a botnet, all sorts of fun and profitable stuff. Hey, you can even make the site make the site’s users your unwitting hosts, too. You don’t go hack a Wordpress site, you go grab a few hundred thousand of them and do industrial scale crimes.
Hizonnerabout 14 hours ago
Why would anybody trust criminals to pay them over time?
idiotsecantabout 13 hours ago
Because if they don't other people will hear they don't pay and won't sell them 0days
dangabout 2 hours ago
Ok, we've taken $500k out of the title above.
monster_truckabout 10 hours ago
What do you think the venn diagram looks like for people willing and able to find things like that prior to LLMs and also sell them to a broker, and are also stupid enough to flaunt a massive flashing "arrest me!!!" sign

Closest you're going to get is something like those kids in florida who just got wrapped for putting malware into steam games and draining peoples accounts. They were going to get caught anyways but it would have taken a lot longer to build a case against them if they weren't flaunting it on socials

nickffabout 8 hours ago
Is this comment pure speculation, or do you have knowledge (or anecdotal evidence) of a similar exploit being sold for $500k?
trollbridgeabout 11 hours ago
"People paid $5,000 for a Macintosh computer when they were new. I found one at a yard sale for $25."
grugqabout 9 hours ago
this is the most accurate summary.
trollbridgeabout 8 hours ago
I actually found a 1999 iMac set out for a special rubbish pick up day. The owner of the house was there so I chatted a bit, asked her if she minded if I took it.

It had last been booted on it, complete with working hard drive an; MacOS X 10.3. So $1.299 -> $0.

nativeitabout 13 hours ago
> modified like they are holy scripture

So never modified at all, even if plainly contradictory and/or ethically and morally compromised?

functionmouseabout 14 hours ago
sloptimists are liars

not big surprise

progbitsabout 17 hours ago
https://github.com/WordPress/WordPress/commit/3a640e1c5e39aa...

String concatenation SQL injection in the year 2026.

sunaookamiabout 16 hours ago
Oh it's even worse: https://developer.wordpress.org/plugins/creating-tables-with...

>Rather than executing an SQL query directly, we’ll use the dbDelta function

>Note that the dbDelta function is rather picky, however. For instance:

>You must put each field on its own line in your SQL statement.

>You must have two spaces between the words PRIMARY KEY and the definition of your primary key.

>You must use the key word KEY rather than its synonym INDEX and you must include at least one KEY.

>KEY must be followed by a SINGLE SPACE then the key name then a space then open parenthesis with the field name then a closed parenthesis.

>You must not use any apostrophes or backticks around field names.

>Field types must be all lowercase.

>SQL keywords, like CREATE TABLE and UPDATE, must be uppercase.

>You must specify the length of all fields that accept a length parameter. int(11), for example.

dupedabout 11 hours ago
Sometimes when you write documentation for APIs you realize something is terribly designed. That should have happened here.
madaxe_againabout 11 hours ago
I like that you chose ten examples.

>> s/you must/thou shalt/g

9devabout 17 hours ago
The WordPress codebase is a disgrace. PHP is a beautiful language by now, but they absolutely butcher it and refuse to do anything about that.
CM30about 16 hours ago
It's just because they don't want to break anything in existing sites, sorta like how Microsoft doesn't generally want to break programs on Windows. So, changes are fairly incremental, and the quality is about what you'd expect from a piece of software that's decades old with no plan for what happens if it got this far.

But what do you do in that situation? If they change the structure too much, then either they make it impossible to upgrade an existing site, or potentially break a whole bunch of things said sites depend on (mostly themes and plugins). And that ease of upgrading is likely what stops a lot of people just migrating away to other solutions.

9devabout 15 hours ago
Even just introducing emulation layers for the old parts and making the new parts opt-in would be better than just giving up and keep on going. Plugin authors can choose the new subsystem as they publish updates or new plugins and themes, and in return they get speed and security guarantees.

And since the WordPress foundation controls the extension marketplace, they can reliably determine which parts of the API surface are in use, or even invest a chunk of money every month to send AI-written patches to plugin maintainers to ease the transition.

There would be so many ways to improve the situation (to the benefit of WordPress maintainers, customers, and ecosystem vendors alike, mind you!), but alas, they are stuck to their ways and will not.

liveoneggsabout 15 hours ago
they broke tons of stuff with Gutenberg/block editor and didn't seem to be bothered by backwards compat
antonymooseabout 7 hours ago
If the existing at-risk functionality is a security issue I feel like that’s a good time to throw the proverbial flag on the play and make it an issue. Letting consumers play host to malware and phishing portals is the worse move.
tonyedgecombeabout 14 hours ago
This isn’t some problem that has developed over time. It was shit from day one.
bilekasabout 16 hours ago
I'm convinced it's by design so that the community that build little businesses around wordpress still stay in the eco system. A client needs new functionality? That's be a week of work because god help anyone who wants to look into themselves.

WordPress is actively degrading the security and quality of the web I general. Has been for many many years.

bayindirhabout 15 hours ago
The great irony is they still sport their "Code is Poetry" mantra on their website [0].

If code is poetry, Wordpress is a new genre of it, probably?

[0]: https://codex.wordpress.org/WordPress_Philosophy

ralferooabout 15 hours ago
chrismorganabout 13 hours ago
If code is poetry, WordPress was written by William McGonagall <https://en.wikipedia.org/wiki/William_McGonagall>.
tiborsaasabout 13 hours ago
They could just go a bit more honest and migrate to "Code is pasta". WP is also closer to a pizza slice than Michelin star fine dining experience.
Yokolosabout 15 hours ago
They never said it was good poetry
bell-cotabout 15 hours ago
Ask an old English teacher whether "poetry" implies anything favorable about quality.
evantbyrneabout 15 hours ago
Everything I've used from Automattic has felt that way. If you ever want to torture an engineer, just make them change the layout of WooCommerce checkout.
asimovDevabout 17 hours ago
As a junior I am glad I happened to start working with PHP on version 7. I had some peeks at our legacy PHP5 stuff (all killed now thankfully) and it looked very different. I am sure it would suck to work with.
thejoshabout 16 hours ago
php7 was such a great time period for PHP, honestly lots of great experimental projects around that time too (HHVM before that, etc).
geek_atabout 17 hours ago
it would help if they used strict types and modern standards but as you say the wordpress codebase is beyond dated and held together with duckt tape
khalicabout 16 hours ago
I remember multiple projects giving up on rewriting it. Maybe a machine with endless patience could do it?
hparadizabout 16 hours ago
I've done it multiple times but no one's gonna use my off the shelf blog when there's a bagilian WordPress plugins they wanna use. But with AI you kinda sorta should just build your own blog. Doctrine with slime framework. You can even throw a WordPress plugin at the LLM and ask it to implement the same thing.
pwillia7about 14 hours ago
tbf literally all my php hate comes directly from WP
mono442about 16 hours ago
PHP is a proof that you don't need elegant or good technical solutions to be successful. You can literally pile up slop together and still be successful.
9devabout 15 hours ago
Yeah; the common idea of dignity and self-respect is to replace the duct tape with proper engineering once you're successful though, instead of just taping ever more of it on top and pretending SQL injections aren't really a problem.
marysol5about 12 hours ago
I think PHP came right at the time that every man and his dog was a "web developer" and writing absolute unknowledgable stuff. And PHP allowed for it.

ASP had a bit of a barrier to entry because it required all the MS. Whereas PHP was everywhere.

hparadizabout 16 hours ago
It was like that in the old days too. Seriously who makes a postmeta table and goes "yea let's just throw everything in here. Indexes? Meh."

I cringe everytime.

cute_boiabout 12 hours ago
I don't think PHP is a beautiful language. If it was Laravel wouldn't need to rewrite every function from standard library. And, I see no reason to use it compared to Typescript.
9devabout 7 hours ago
I never really understood these complaints about the standard library, that's not what makes a language really. Yes, it's ugly, yes, it carries 30 years of baggage, but it's PHP the language that allows you to interact with a much more convenient abstraction layer provided by Laravel.

PHP can run the same code fully dynamically typed or with very strict type annotations, depending on your requirements. It has runtime reflection APIs that are so cheap that you don't really have to think about using them. You can do OOP or FP with PHP, or even procedural HTML-interleaved-with-PHP if that's your thing. It has late static binding, so you can defer to child classes from their parent class. There are generators and fibres as first-class language constructs now. Property hooks are an extremely clear pattern, way better than in many other languages.

Generally, there have been tons of new syntax extensions over the years, and they all slot in gracefully. With PHP 8.6, we're going to get partial application for functions, which will make PHP 8.5's match expressions one of the most ergonomic implementations I have seen yet!

sofixaabout 12 hours ago
Ecosystem? The JS/TS ecosystem approach is to use as many libraries as possible for the sake of it, exposing you to a massive supply chain risk. PHP doesn't suffer from that because there are barely any libraries for it.
dinkelbergabout 17 hours ago
What an awful fix. Does WordPress seriously still use basic string concatenation (edit: and sprintf) to build SQL queries?
Yokohiiiabout 16 hours ago
To construct dynamic sql queries to have to string concatenate at least some parts, .

User data should of course be passed via prepared statements.

codedokodeabout 11 hours ago
One usually uses "query builder" pattern for that.

Also, regarding placeholders, historically many DB and frameworks do not support passing lists for a value in a placeholder (like "WHERE id IN(?)") so users of such software fall back to string concatenation.

formerly_provenabout 15 hours ago
Not user code, no. Someone eventually has to, but virtually every ORM under the sun allows you to construct dynamic queries without having to concatenate strings yourself or resort to string interpolation.
reddaloabout 16 hours ago
WordPress source code is a mess. They should re-write it from scratch using modern technologies, or even a framework like Laravel.
mewpmewp2about 15 hours ago
That could as well just be a complete new product then, right?

It would definitely be a breaking change and unmigratable.

mapmeldabout 15 hours ago
A few months back, Cloudflare used AI to make a Rust rewrite of WordPress, but I doubt that they would have found or corrected issues like this on the way? https://blog.cloudflare.com/emdash-wordpress/
plucabout 15 hours ago
Mullenweg will never allow WP to slip away from his control. "He wrote it" so you can't have it.
sourcecodeplzabout 16 hours ago
Who is they? automaticc?
dncornholioabout 14 hours ago
Impossible. WordPress has had the PHP-group even considering writing new PHP features in a separate 7.4 branche and release them specifically for WP.
SpikedColaabout 12 hours ago
Ahhh very interesting! Thanks for pointing this out, I saw an attack against one of our sites this weekend using this exploit.

> data: {'requests': [{'method': 'POST', 'path': 'http://:'}, {'body': {'requests': [{'method': 'GET', 'path': 'http://:'}, {'method': 'GET', 'path': '/wp/v2/widgets?author_exclude=1%29+AND+1%3D0+UNION+ALL+SELECT+0%2C1%2C0x323...

m00dyabout 16 hours ago
>>Principal Software Engineer @ Bluehost. WordPress Core Committer. Baseball fan.

hmm yes, definitely. You are the principal.

hmokiguessabout 14 hours ago
I am so done with FOMO writing. Sure man, you found one with $25. With $25 plus your entire industry domain specific knowledge of where to look, of how to probe, of what else you may have accumulated and collected over the years of working within this industry. Let's stop with the gambling narrative and the illusion that we are all missing out.
w4yaiabout 14 hours ago
I agree. This is so toxic! It feels like the Instagram of articles. "Look how my life is great" - yeah sure, you're posting only happy moments.

Not only $25 is not accounting the years of experience, but also all the failed attempts.

paodealhoabout 9 hours ago
Should also note the math done on the token costs. $25 of subsidized tokens because he's on a subscription plan.
recitedropperabout 12 hours ago
I can't agree with this more. May cooler, more compassionate minds prevail.
deatonabout 11 hours ago
And nobody would post "I did it for free!" if they had done it themselves, but somehow spending $25 on tokens changes how we're supposed to look at it
ameliaquiningabout 1 hour ago
I might be missing something, so perhaps someone can explain: Why are the steps in the middle of the exploit chain necessary? The writeup describes getting a SQL injection, then going from there to cache poisoning to exploiting various logic bugs, to eventually creating an admin account (and WordPress grants RCE to admin accounts by design). But if you have a SQL injection, why can't you use that to just create an admin account directly, by inserting it into the users table?
ahartmetzabout 17 hours ago
The surprising (and possibly untrue) thing is the high price of canned vulnerabilities. WordPress is known as the remote root shell with a blogging feature.
denysvitaliabout 16 hours ago
I still don't understand why, for a blog, a static page isn't enough - especially since most of the WordPress issues are "solved" by adding caching.

I do understand it from an user perspective (it's easier to tell the average user to drag and drop rather than committing to a GitHub repo and letting hugo build the website), but from a security standpoint WordPress is really just waiting for a vulnerability (either in the core or on the thousands of plugins) in order to unlock its RCE-as-a-service functionality.

muvlonabout 14 hours ago
In many deployments, Wordpress started out as just a blog that is easy to edit right from the web browser, but then grew into way more. Most commonly, people end up retrofitting all kinds of e-commerce features onto it, and that's how you really get into the whole plugin mess. At that point, for better or worse, the Wordpress instance is serving important business needs that are not addressed by a static page.
marysol5about 12 hours ago
It went from a blog, to an entire CMS. Which is bonkers
CM30about 15 hours ago
People like having a WYSIWYG editor, being able to update their posts in the browser, having comments and being able to use plugins. They're also not particularly skilled with the terminal/commands, and a lot of hosts provide a one-click install setup for scripts like WordPress.
mewpmewp2about 15 hours ago
Like you said. It is a product for people who are not technical and don't code. A product that you would have to use git for, wouldn't be used by the 90 percent in the first place. And there are such products. There is a reason WordPress is the most popular platform. Most people are not technical.

And people like to be able to extend from Blogs to various other non static features which WordPress allows for.

thenthenthenabout 14 hours ago
Its so funny… our wordpress started off as simple blogging thing but now is not only using 99% cpu but also no one knows how to edit/deal with all the plugins etc. Wordpress is the worst choice. Always
acomjeanabout 15 hours ago
The non-profit I help with moved to Wordpress so people can edit the site without having to use git. (We have a lot more editors now)..
1123581321about 14 hours ago
- Anyone can edit it

- Less training; org probably has someone who’s used Wordpress before. (Yes, training. You must deal with the reality of the typical user.)

- In the developing group or agency, anyone can work on the theme if you install a theme builder. An agency can put a cheaper content marketer or designer on it, rather than a developer.

pwillia7about 14 hours ago
WPE tried to make Faust.js a thing so you could use WP CMS but generate a modern static site but I don't think it really took off much
gorszonabout 17 hours ago
Propably untrue, the only way to know is to do threat intelligence, and inflitrate those telegram groups where these brokers operate, I doubt the writer of the article did that. Maybe he conflated any vulnerability with a 0-day one?
blauditoreabout 16 hours ago
...or was just looking for a clickbait title.

Surely someone once offered a vulnerability for 500k somewhere, but that doesn't mean someone bought it.

slimabout 14 hours ago

  WordPress is one of the most hardened targets of all time
that obsolete code did not change for decades. all the bugs have been discovered and patched
lyu07282about 17 hours ago
some statistics point to almost 50% of all websites on the internet running on Wordpress, $500k for an undisclosed 0day unauthenticated RCE doesn't seem so unrealistic to me
addedlovelyabout 15 hours ago
I've got it at 38.32%. I'm looking at the 'front-door' of the web, active sites, no subdomains, from Crux user experience data.

Will be publishing a report on www.theweb.report soon - if you're interested.

That's a seed of about 13 million domains - pretty sure WordPress would be dominating the even longer tail.

( Also worth noting it's sooo easy to detect a site is WordPress, it screams it across every signal we gather, where-as some sites are just well made and have limited information leaks ).

raesene9about 17 hours ago
Interesting write-up and I do think LLM assisted/powered exploit disclosure is a real concern (I've been able to get models to create container breakouts from Linux LPEs relatively quickly).

One thing I'm surprised about is that GPT-5.6 didn't block that prompt due to guardrails. My experience is that GPT-5.5 and up does not like offensive security work (similar to Opus 4.7+/Fable).

I didn't notice it but I'd assume that the authors have some level of cyber approvals from OpenAI to relax the guardrails a bit.

Santasabout 16 hours ago
This might help https://chatgpt.com/cyber ease the guardrails a bit.
eruabout 16 hours ago
Thanks! I wonder if Claude has something similar?
NiekvdMaasabout 15 hours ago
lillesvinabout 14 hours ago
I feel like I've seen plenty of non-AI, pre-2020 SAST tools catch SQLis like the one mentioned here, and if nothing else, then a code review ought to catch it. Is WordPress not using code reviews and/or SAST?
f311aabout 10 hours ago
They would not catch it, it requires combining multiple vulns.
secretslolabout 9 hours ago
One of my websites was hacked with this, luckily not one with any users at all.

They did this:

- Two admin accounts in the database.

- plugin dir: wp-content/plugins/wp-core with remote command-execution web shell wp-core-[12 random chars].php

- firewall.php backdoor in mu-plugins dir with admin on GET ?sergei

- cache-seo-helper.php backdoor

- fixer.php which renames the wordpress version number to one which is patched.

I have decided to give up on Wordpress.

lexicalityabout 16 hours ago
The author lost me at the last bit where they started using weird names for the posts. Why would you make one ID O and the other ID 0? Why single letters and not EMBED_01? Why seemingly random letters instead of ABCDEF? Does OCPDST stand for something?
moebrowneabout 16 hours ago
They are placeholders, their meanings are spelled out in the post:

    O: publish/oembed_cache, empty content, stale timestamp with parent C
    C: future/customize_changeset, changeset JSON with parent C
    P: draft/page, with parent D
    D: parse/request with itself as its parent
    S: publish/post, for providing embed data
    T: publish/post, containing the outer embed
lexicalityabout 8 hours ago
That doesn't actually answer any of my questions though. Why is `S` the placeholder for "post"? T for T'outer?
cromkaabout 17 hours ago
This assumes those who'd pay $500k don't have the skill to use GTP5.6 for the same purpose themselves?
elmer2about 14 hours ago
Then why didn't we see the same writeup earlier? If you look through the writeup, you still need the skills to go through what the LLM gives you and actually create a valid proof of concept.

I've been using LLMs to find security vulnerabilities and there is no way I can just submit what I found and call it a day (many try).

cheschireabout 16 hours ago
You read articles regularly about how X authority is provided cloud LLM history and uses it as evidence to prosecute a defendant.

Yet you think professional criminals are too stupid to launder their activities through an unscrupulous yet legal intermediary?

khursabout 16 hours ago
People who make the money are not necessarily the people who can write the best code.

Elon Musk didn't write code for a rocket, he hired people who could.

ifdefdebugabout 17 hours ago
> Is GPT5.6 Sol Superhuman?

This is not a simple y/n question. Computers have been superhuman at playing chess for decades now. Reading this article, I guess they are superhuman at understanding code now as well.

chrisjjabout 17 hours ago
> Computers have been superhuman at playing chess for decades now.

And at doing arithmetic for even longer /i

Advertisement
barbazooabout 8 hours ago
I'd expect the amount of money paid for exploits to go down then. It's inefficient to pay >$25 for an exploit that took $25 to make.
cadamsdotcomabout 15 hours ago
That was an incredible writeup! Chapeau to the author - thanks for taking the time to do a writeup.

When Anthropic claimed Mythos chained 4 or 5 bugs to achieve sandbox escape and found bugs in core software, it sounded like bs. But here we are 2 months later seeing what they meant.

Cybersecurity was always a hard sell; security flaws were invisible - by contrast a fence with a hole is visible to everyone - anyone can ignore the locked gate and walk through the fence hole. With cybersecurity a hole in the fence may go unnoticed for years, maybe forever.

LLMs level the field. We will all benefit from more secure systems, a few people will get a lot of egg on their faces, and it will end the malpractice of underinvesting in software security to get a product out the door.

alienbabyabout 15 hours ago
| We will all benefit from more secure systems

the people that can afford it, sure.

s3pabout 14 hours ago
Can some people not afford open source software?
dzongaabout 15 hours ago
wordpress is so shitty - though it runs the majority of the web.

people think PHP is shitty cz of Wordpress.

at a certain point in time - people need to move to better ecosystems painful as that may be.

f311aabout 10 hours ago
Historically, a lot vulnerabilities in PHP projects were because of PHP itself. Things like register_globals, remote includes/reads using functions that supposed to read local data and so on.
vavkamilabout 17 hours ago
This one is both awesome and scary. We are living in a black mirror episode, where one well-crafted LLM prompt can get you $500k or the ability to hack into 500M websites :)
wongarsuabout 17 hours ago
The market will quickly adjust to the point where spending $50 on tokens will on average give you a vulnerability valued at $50. Maybe $100 to account for your edge in having a better prompt and the risk of prison time you take in selling the exploit

In fact that may well be true today. OP didn't try to sell it to discover the true price the market is willing to pay. And we all know that "somebody paid $$$ for something similar in the past" is no guarantee that somebody else is willing to pay any significant sum for your thing today. If it was, startups would be a lot easier

hopppabout 17 hours ago
I don't think OP got $500k , it's only clickbait in the title.
Philip-J-Fryabout 17 hours ago
One LLM prompt can't get you $500K. Why would someone spend $500k instead of just prompting themselves?
inigyouabout 17 hours ago
Because they don't know you can
muldvarpabout 11 hours ago
I think anyone willing to pay $500k is well aware that LLMs can be used to find vulnerabilities.
cbg0about 17 hours ago
Don't get all starry-eyed, the people owning those sites also have access to LLMs, so both the hacks and paydays are rare.
throwitaway222about 9 hours ago
Seems like exploit brokers can just buy a codex license and put the 500k towards finding all bugs in all software for the price of one bug
_superposition_about 16 hours ago
The cost of business nowadays? At what point does it become apparent that in today's world software needs continuous pen testing and scanning? If you don't your attackers will.
alienbabyabout 15 hours ago
| in today's world software needs continuous pen testing and scanning

points to a bigger problem perhaps; software design, construction and distribution is fundamentally flawed.

tantalorabout 14 hours ago
Is this real? Or did they concoct this vulnerability just to write a blog post?

I'm not seeing any mention where they report this to WP or the patch.

r1chabout 14 hours ago
Does Sol allow this kind of research by default or is this a "look at me I'm on the cyber research allowlist" post?
_joelabout 13 hours ago
The "pro's buy out a company that has a massive add-on install base with the most non-technical users.
mixtureoftakesabout 17 hours ago
What was the harness used? And yeah surprised about such prompts not being downright blocked, even with the cybersafety verification"
Advertisement
aussieguy1234about 17 hours ago
So they spent the $25. But the real question here is did they get the $500K?
az226about 8 hours ago
Unquestionably they did not.

Their listed pricing was up to $50k.

https://cyber-peace.org/wp-content/uploads/2017/09/ZERODIUM-...

And that was before LLMs could produce these at volume.

The demand (dollars) does not go up commensurately with the supply. So today maybe $500 or a few thousand. Maybe not even that.

elmer2about 14 hours ago
Probably not. The Wordpress Bug Bounty program pays very little. Exploit brokers will pay 500K, but we wouldn't be seeing it here if it was sold.
preetham_ranguabout 17 hours ago
Nice balance between practicality and ambition. Curious how it holds up with real-world scale.
joriswabout 17 hours ago
RCE — Remote code execution
sashank_1509about 10 hours ago
Thanks
perarnengabout 14 hours ago
How do you find exploits without risking someone seeing your attempt and reporting you as a hacker? do you register first somewhere?
kamranjonabout 14 hours ago
You can run Wordpress locally in your own sandbox to test these vulnerabilities, you don’t have to break any laws.
CodeCompostabout 17 hours ago
I like the idea of not crediting the person who posted the bug but to the LLM that found it. People who find exploits using LLMs should never get a reward or credit.
pelagicAustralabout 17 hours ago
So people coding with LLMs shouldn't get paid then, right?
grey-areaabout 17 hours ago
That is in fact the end goal of CEOs pushing LLM use yes. Not possible right now, but if it were they would absolutely take that option.
joriswabout 17 hours ago
[citation needed]
muldvarpabout 11 hours ago
Do you assume that five years from now you'll get paid for coding with LLMs?
bakugoabout 16 hours ago
Correct.
chrisjjabout 16 hours ago
They should get paid by the LMM only.
Levitzabout 16 hours ago
It baffles me how this can be said without concern for first order consequences.
nubgabout 17 hours ago
I agree! We should go all the way though and credit the authors of the data the LLM was trained on. People who just run LLMs training scripts should never get a reward or credit.
defmacr0about 16 hours ago
I take credit given all my infosec-related reddit posts they used for training.
j45about 8 hours ago
I wonder if there could be a crowdfunding to harden Wordpress with the leading models, or some who might have access to something like a Mythos level.
staredabout 15 hours ago
On another note - who needs WordPress in the age of Astro and LLMs?

I mean, it's not a taunt, but a serious question - do people keep WordPress because it used to be the easiest solution to set up years ago, or are there still clear use cases where one can argue it's the best solution?

justanotherunitabout 15 hours ago
I have not yet seen an alternative for Wordpress + woocommerce for a simple e-commerce site that is not more expensive. I am open for alternatives tho if anyone knows any
crummyabout 15 hours ago
does Astro do WYSWIYG?
IshKebababout 17 hours ago
Presumably they don't pay $500k anymore...
rvzabout 17 hours ago
Just like that, the 0-day black market is experiencing a mini black Monday.
yellow_leadabout 17 hours ago
Can RCEs like this still be sold to exploit brokers like Zerodium? If so, how? Asking for a friend
titularcommentabout 12 hours ago
lol. Simple case of if you have to ask, you probably shouldn't.
Advertisement