ex: Target hits website -> site delivers RCE for some software that is on the target's system
I'd disagree here. Still 41% of all sites use Wordpress [1]... and that means a lot of targets, and a lot of ways to target them. Your good ole' deface/ransomware extortion scheme, leaking data supposed to be confidential (such as account lists), trusted spreaders for exploits, or the latest hit, bets on "prediction markets" that have some Wordpress site set as oracle. People are willing to screw around with airport weather stations to manipulate bets [2], it's not that much of a stretch to assume such incentives would also apply for website hackers.
[1] https://www.wpzoom.com/blog/wordpress-statistics/
[2] https://edition.cnn.com/2026/04/23/europe/france-weather-sen...
You also don't need an RCE for 99% of that.