Aren’t WP exploits valuable for watering hole attacks?
You don't need an RCE for that though. There's a lot of vulnerable plugins deployed everywhere.
Ok, but an RCE in WP Core still seems pretty dang valuable, especially if you want to hit non-commercial websites that are less likely to have as many plugins installed?
You already owned the WordPress admin with your browser 0day, you don’t care if WordPress is secure or not.
You don't need an RCE for that though. There's a lot of vulnerable plugins deployed everywhere.
Ok, but an RCE in WP Core still seems pretty dang valuable, especially if you want to hit non-commercial websites that are less likely to have as many plugins installed?
You already owned the WordPress admin with your browser 0day, you don’t care if WordPress is secure or not.