wp2shell

A tortoiseshell is quite unlike a wp2shell. Credit Maddydumont.
Last Friday, a new and extremely serious vulnerability in WordPress was announced. To summarise, WordPress installs from 6.9 onwards (roughly December 2025) can be compromised remotely, allowing attackers to gain full access to the hosting account that it is running on.
We ensured that all Managed WordPress sites were upgraded promptly, as we do with all vulnerability announcements affecting WordPress and its plugins. As it happens, many of our managed sites were not vulnerable due to some custom hardening rules that we apply by default to managed installations.
We also have a large number of customers running unmanaged WordPress installations on our hosting accounts. Maintaining the security of these installations is the customers’ responsibility and we generally try to avoid interfering with customer sites. In this case, the severity of the vulnerability, and the speed with which we saw exploitation attempts, meant that we felt compelled to take action.
Many users don’t take security too seriously, assuming that their site isn’t important enough to be a target. The reality is that all sites are a target, as compromised hosting accounts can be used to send spam email, or host malicious files for other attacks, and cleaning up after an attack is a lot of work for everyone.
The exploit can be prevented by a simple and non-invasive addition to a site’s .htaccess file that blocks requests to certain URLs. Therefore, we took the step of scanning our hosting servers for WordPress installations that hadn’t been updated (most sites will update themselves automatically) and added the necessary rules, along with a comment explaining why it was done.
Of course, if you don’t want to spend your Friday evenings worrying about critical security updates, our Managed WordPress is still welcoming new customers.