Live data from Hacker News

I found a WordPress RCEs with GPT5.6 and $25

slcyber.io

181–190 of 247 posts

Re: I found a WordPress RCEs with GPT5.6 and $25

#181
One of my websites was hacked with this, luckily not one with any users at all.

They did this:

- Two admin accounts in the database.

- plugin dir: wp-content/plugins/wp-core with remote command-execution web shell wp-core-[12 random chars].php

- firewall.php backdoor in mu-plugins dir with admin on GET ?sergei

- cache-seo-helper.php backdoor

- fixer.php which renames the wordpress version number to one which is patched.

I have decided to give up on Wordpress.

Re: I found a WordPress RCEs with GPT5.6 and $25

#183

There is no evidence that $500k has been paid or would be paid for an exploit like this one. Given that the article says that prompts are modified like they are holy scripture, perhaps sell the prompt for $500k. The author works for https://www.assetnote.io/ , which has AI products for automated scanning.

"People paid $5,000 for a Macintosh computer when they were new. I found one at a yard sale for $25."

this is the most accurate summary.

Re: I found a WordPress RCEs with GPT5.6 and $25

#184

Earlier quoted context omitted.

they broke tons of stuff with Gutenberg/block editor and didn't seem to be bothered by backwards compat

Not only did they break classic WordPress stuff, but they also keep breaking Gutenberg APIs at a really frustrating rate. It’s clear that the core WordPress developers have a very different idea of project stewardship than the Gutenberg devs do.

Blame Matt Mullenweg

Re: I found a WordPress RCEs with GPT5.6 and $25

#185

I am so done with FOMO writing. Sure man, you found one with $25. With $25 plus your entire industry domain specific knowledge of where to look, of how to probe, of what else you may have accumulated and collected over the years of working within this industry. Let's stop with the gambling narrative and the illusion that we are all missing out.

Should also note the math done on the token costs. $25 of subsidized tokens because he's on a subscription plan.

Re: I found a WordPress RCEs with GPT5.6 and $25

#186

Earlier quoted context omitted.

Wordpress is a great web shell, shame it also comes with a blog

Is it? I did a project with WP a very long time ago and was kind of baffled. Like it's nice to have an good rich text editor, I got that part. But the absolute monstrosities people developed to extend WP, when they could have just used MySQL and PHP directly, astounded me. Like I couldn't figure out what WP was offering? It was just like a blog that you could painfully hack into something else if you wanted to. But e…

You may be missing the point that the WP ecosystem is aimed at non-programmers.

Re: I found a WordPress RCEs with GPT5.6 and $25

#187

Earlier quoted context omitted.

[flagged]

Why would you reply with something completely unsubstantiated that anyone in security at that time worth their salt would be able to call you out on and then in subsequent comments call people liars for insisting it did, in fact, exist? I’m just baffled.

The pricelist was a marketing stunt.

Re: I found a WordPress RCEs with GPT5.6 and $25

#188
post #121

Earlier quoted context omitted.

Likely referencing https://www.crowdfense.com/exploit-acquisition-program/ Zerodium used to offer up to 300k in 2021 https://www.securityweek.com/sites/default/files/images/Zero... These brokers usually don't pay the bulk sum - they sell access to nation actors and you get payed out over time as long as the bug is not patched to discourage reselling and burning it. I doubt anyone would confirm if they got the full pa…

I work in the field and I just cannot believe anyone would pay that much for a Word Press exploit. People pay money for iOS or Android because there is valuable information stored on devices running those operating systems. There's absolutely nothing of value on any Word Press site. The only possible reason I can think of is for a watering hole attack, but that would require a second exploit that would be worth far m…

Remember the Panama papers? That was a Wordpress hack.

Re: I found a WordPress RCEs with GPT5.6 and $25

#189

The author lost me at the last bit where they started using weird names for the posts. Why would you make one ID O and the other ID 0? Why single letters and not EMBED_01? Why seemingly random letters instead of ABCDEF? Does OCPDST stand for something?

They are placeholders, their meanings are spelled out in the post: O: publish/oembed_cache, empty content, stale timestamp with parent C C: future/customize_changeset, changeset JSON with parent C P: draft/page, with parent D D: parse/request with itself as its parent S: publish/post, for providing embed data T: publish/post, containing the outer embed

That doesn't actually answer any of my questions though. Why is `S` the placeholder for "post"? T for T'outer?

Re: I found a WordPress RCEs with GPT5.6 and $25

#190
post #121

Earlier quoted context omitted.

Likely referencing https://www.crowdfense.com/exploit-acquisition-program/ Zerodium used to offer up to 300k in 2021 https://www.securityweek.com/sites/default/files/images/Zero... These brokers usually don't pay the bulk sum - they sell access to nation actors and you get payed out over time as long as the bug is not patched to discourage reselling and burning it. I doubt anyone would confirm if they got the full pa…

I work in the field and I just cannot believe anyone would pay that much for a Word Press exploit. People pay money for iOS or Android because there is valuable information stored on devices running those operating systems. There's absolutely nothing of value on any Word Press site. The only possible reason I can think of is for a watering hole attack, but that would require a second exploit that would be worth far m…

Bulk reply to all the people replying.

bink is correct. The people who buy exploits are governments. There is very little interest in Wordpress or indeed any target that isn't a browser or a mobile. Browsers and mobiles are the only things that are perennially useful to an intelligence agency. Those two are reliable access vectors for the vast majority of things that interest government organisations.

Post reply on HN