Live data from Hacker News

I found a WordPress RCEs with GPT5.6 and $25

slcyber.io

121–130 of 247 posts

Re: I found a WordPress RCEs with GPT5.6 and $25

#121

There is no evidence that $500k has been paid or would be paid for an exploit like this one. Given that the article says that prompts are modified like they are holy scripture, perhaps sell the prompt for $500k. The author works for https://www.assetnote.io/ , which has AI products for automated scanning.

Likely referencing https://www.crowdfense.com/exploit-acquisition-program/ Zerodium used to offer up to 300k in 2021 https://www.securityweek.com/sites/default/files/images/Zero... These brokers usually don't pay the bulk sum - they sell access to nation actors and you get payed out over time as long as the bug is not patched to discourage reselling and burning it. I doubt anyone would confirm if they got the full pa…

I work in the field and I just cannot believe anyone would pay that much for a Word Press exploit. People pay money for iOS or Android because there is valuable information stored on devices running those operating systems. There's absolutely nothing of value on any Word Press site. The only possible reason I can think of is for a watering hole attack, but that would require a second exploit that would be worth far more (and they aren't).

Re: I found a WordPress RCEs with GPT5.6 and $25

#122
post #43

Earlier quoted context omitted.

I remember multiple projects giving up on rewriting it. Maybe a machine with endless patience could do it?

I've done it multiple times but no one's gonna use my off the shelf blog when there's a bagilian WordPress plugins they wanna use. But with AI you kinda sorta should just build your own blog. Doctrine with slime framework. You can even throw a WordPress plugin at the LLM and ask it to implement the same thing.

did you mean Slim, the PHP framework? When I google 'slime framework' i get some machine learning stuff

Re: I found a WordPress RCEs with GPT5.6 and $25

#123

Earlier quoted context omitted.

I still don't understand why, for a blog, a static page isn't enough - especially since most of the WordPress issues are "solved" by adding caching. I do understand it from an user perspective (it's easier to tell the average user to drag and drop rather than committing to a GitHub repo and letting hugo build the website), but from a security standpoint WordPress is really just waiting for a vulnerability (either in…

Like you said. It is a product for people who are not technical and don't code. A product that you would have to use git for, wouldn't be used by the 90 percent in the first place. And there are such products. There is a reason WordPress is the most popular platform. Most people are not technical. And people like to be able to extend from Blogs to various other non static features which WordPress allows for.

Its so funny… our wordpress started off as simple blogging thing but now is not only using 99% cpu but also no one knows how to edit/deal with all the plugins etc. Wordpress is the worst choice. Always

Re: I found a WordPress RCEs with GPT5.6 and $25

#124
post #72
post #35

Earlier quoted context omitted.

WordPress source code is a mess. They should re-write it from scratch using modern technologies, or even a framework like Laravel.

A few months back, Cloudflare used AI to make a Rust rewrite of WordPress, but I doubt that they would have found or corrected issues like this on the way? https://blog.cloudflare.com/emdash-wordpress/

TypeScript, not Rust.

Re: I found a WordPress RCEs with GPT5.6 and $25

#127

Earlier quoted context omitted.

Of course it is. It just no longer exists.

Oh, you've done business with them then? Know someone who has?

Yes actually, I know someone who did business with them many years ago (before the advent of LLMs), although for a smaller sum than the advertised top payouts (the vulnerability they had was much less important).

Why post these random unsubstantiated claims on HN?

Re: I found a WordPress RCEs with GPT5.6 and $25

#129

Earlier quoted context omitted.

Likely referencing https://www.crowdfense.com/exploit-acquisition-program/ Zerodium used to offer up to 300k in 2021 https://www.securityweek.com/sites/default/files/images/Zero... These brokers usually don't pay the bulk sum - they sell access to nation actors and you get payed out over time as long as the bug is not patched to discourage reselling and burning it. I doubt anyone would confirm if they got the full pa…

Why would anybody trust criminals to pay them over time?

Because if they don't other people will hear they don't pay and won't sell them 0days

Re: I found a WordPress RCEs with GPT5.6 and $25

#130
post #18

Earlier quoted context omitted.

The WordPress codebase is a disgrace. PHP is a beautiful language by now, but they absolutely butcher it and refuse to do anything about that.

The great irony is they still sport their "Code is Poetry" mantra on their website [0]. If code is poetry, Wordpress is a new genre of it, probably? [0]: https://codex.wordpress.org/WordPress_Philosophy

They could just go a bit more honest and migrate to "Code is pasta". WP is also closer to a pizza slice than Michelin star fine dining experience.
Post reply on HN