the WordPress sites getting owned by wp2shell all have one thing in common — and it isn't bad luck

If your WordPress lives on managed hosting, you were probably patched before you'd even read the news. The sites actually exposed to wp2shell share…

Aliteq
Priya Nair · Software & Systems Editor

The short answer

Managed WordPress hosts largely neutralised wp2shell server-side — via fleet-wide virtual patching (a WAF rule blocking the exploit) and forced core updates — often within hours of disclosure,…

Managed hosts patch once at the platform level and protect every site behind them simultaneously — the same reason a forced auto-update exists, applied by the host.

Virtual patching (a WAF rule) can block an exploit pattern before the site itself is updated — buying protection during the dangerous PoC-is-public window.

Self-hosted sites depend on the owner to patch, and are the ones the forced update can miss if auto-updates are off or the server can't phone home.

The fix for the exposed group isn't necessarily 'move to managed' — it's 'add the layers managed hosts give you': auto-updates on, a WAF in front, fast patching.

Aliteq

Read the full story

the WordPress sites getting owned by wp2shell all have one thing in common — and it isn't bad luck

Read the full story on Aliteq