WordPress website owners should take immediate action following the discovery of a critical security vulnerability in WordPress.
Unlike many security issues that are found in third party plugins or themes, this vulnerability exists within WordPress itself, making it particularly serious. If your website is running an affected version, we strongly recommend taking action as soon as possible.
What is the wp2shell Vulnerability?
Security researchers have identified a critical vulnerability, known as wp2shell, which affects WordPress Core.
The vulnerability could potentially allow an attacker to remotely execute malicious code on a vulnerable website without needing to log in first. This type of vulnerability is considered one of the most serious because it could allow a compromised website to be taken over, used to distribute malware, or expose sensitive data.
Affected WordPress Versions
The vulnerability affects the following versions of WordPress:
- WordPress 6.9.0 to 6.9.4
- WordPress 7.0.0 to 7.0.1
If your website is running WordPress 6.8.5 or earlier, it is not affected by this specific vulnerability.
Why Should You Act Quickly?
WordPress powers more than 40% of websites worldwide, making it an attractive target for cyber criminals.
When vulnerabilities are publicly disclosed, attackers often begin scanning the internet within hours looking for websites that have not yet been updated.
Delaying updates can significantly increase the risk of:
- Website compromise
- Malware installation
- Data theft
- Spam or phishing attacks
- Loss of customer trust
- Damage to brand reputation
- Search engine penalties and blacklisting
What Should You Do?
1. Upgrade WordPress Immediately
If your website is running WordPress 6.9.0 – 6.9.4 or WordPress 7.0.0 to 7.0.1, upgrade to WordPress 7.0.2 immediately, as this contains the security fix.
Before updating, ensure you have a complete backup of your website and database. We recommend performing all updates on your website’s staging environment first, and testing to ensure no functionality has been impacted by the update before you apply the changes on your live environment.
2. Keep WordPress, Plugins and Themes Updated
Many successful website attacks happen because updates are delayed or not done at all.
We recommend:
- Updating WordPress Core as soon as security releases become available
- Keeping all plugins updated
- Keeping themes updated
- Removing all inactive plugins, themes and code that is no longer in use
Outdated software remains one of the biggest security risks for any website.
3. Protect Your Website with a Firewall
A Web Application Firewall (WAF) provides an additional layer of protection by blocking malicious requests before they ever reach your website.
Even when new vulnerabilities emerge, a properly configured firewall can often reduce the risk while updates are being applied.
Additional Security Best Practices
We also recommend reviewing the following security measures for your WordPress website:
Ensure Ongoing Security Updates are Completed
Applications like WordPress and its associated plugins regularly release software updates to maintain security for your website, however many people do not realise that these updates are not set to automatically take place. Whilst you can set some updates to happen automatically, we recommend manually performing these updates away from your live website initially, to allow you to test the impact of system updates on your site’s user experience before pushing them live.
The only thing worse than a security risk is having an update crash your website or make it unusable without you realising, or at a time when your developers are not around to fix it.
Use Strong Authentication
- Enable Two Factor Authentication (2FA) for administrator accounts
- Use strong, unique passwords
- Remove unused administrator accounts
Take Regular Backups
Something you can easily automate are website backups. Ensure your website is backed up on your server automatically every day and that backup restoration is regularly tested.
A backup is only valuable if it can be restored successfully.
Note: When setting up backups, be mindful of your server’s space and resources. Set rules around deleting old back ups so they don’t take up space and stop your site from functioning.
Monitor Website Activity
Security monitoring can detect unusual behaviour before it becomes a major issue.
Look for:
- Unexpected file changes
- New administrator accounts
- Failed login attempts
- Malware alerts
- Unusual traffic patterns
Review Hosting Security
Your hosting environment plays a significant role in protecting your website. Ensure your hosting includes:
- Server level firewall protection
- Malware scanning
- Regular security patching
- Secure backups
- SSL certificates
- Intrusion detection where possible
- Encrypted data at rest
Protect Security Keys and Credentials
A big factor in your website’s security is only the way it stores and manages sensitive credentials. Unfortunately, it is still common to find API keys, passwords and authentication tokens stored directly within application code or configuration files, leaving sites vulnerable.
To reduce the risks, we recommend:
- Never storing passwords, API keys or secret credentials directly within your website’s source code
- Using secure environment variables or encrypted secret management solutions to store sensitive information
- Implementing secure authentication and access control platforms such as Auth0 to manage user authentication, password policies and access permissions
- Regularly rotating passwords, API keys and access tokens, particularly after staff changes or if there is any suspicion of compromise
- Enabling Multi Factor Authentication (MFA) wherever possible for administrators and privileged users
How CDA Can Help
At CDA, we actively monitor emerging security threats affecting WordPress, Magento and other platforms, and offer support packages to help keep maintain the security and performance of websites, mobile apps and other software applications.
If you’re unsure whether your website is affected, we can:
- Check your current WordPress version
- Safely upgrade WordPress
- Update plugins and themes
- Carry out security audits
- Install and configure a Web Application Firewall
- Remove malware if your website has already been compromised
- Put ongoing maintenance and monitoring in place to reduce future risk
Do You Need Support?
If you’re concerned about your website’s security or would like us to review your WordPress set up, our team is here to help.
A proactive approach to website security is far less costly than recovering from a successful cyber-attack.
Get in touch with CDA today to arrange a WordPress security review and discuss WordPress support.
