Skip to content

Comment on WordPress Core is Secure

Comments

Does WordPress have a pwn2own style event? That would prove this more effectively.

Maybe, but remember that it's not just the money for Pwn2Own; it's also that the Pwn2Own contest uses prestige targets. It's probably not quite true that nobody cares if you find a Wordpress vulnerability, but it's certainly nothing resembling weaponizing a Chrome vulnerability.

Assuming the competition is attacking the core (with no 3rd party or themes), wouldn't the 64 million installs be the prestige given all of them could then be an attack vector to the billions of pageviews they serve?

No, the number of Wordpress installs does not make Wordpress a more prestigious target for real vulnerability researchers.

Serious Wordpress, Joomla! or Drupal vulnerabilities and exploits can still get you a few thousand dollars. Quite a high ROI because the vulnerabilities are easier to find than in Chrome.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.