I have seen many companies getting hacked through vulnerabilities that had recently released exploits, while I was working with an incident response team. I believe in most case the CVE was available for some time before the exploit code was made public but no one was aware of the CVE and its implications so they didn't apply the patches. I don't think the researcher is inviting trouble but once the exploit becomes public there is a greater chance of the vulnerability being actively exploited.
Shameless plug: I've been working on a project called https://hacktrack.info, that lets the user track the software they use and get an email alert when new CVEs are released for their stack.