App to Identify wp2shell Vulnerability on WordPress
If your WordPress has automatically installed an update, this is the retroactive PSA on why WordPress has urgently issued one. If it hasn’t, consider it an urgent PSA. There is a vulnerability in WordPress Core, disclosed July 17, affecting 6.9.0–6.9.4 and 7.0.0–7.0.1. The attack surface is Core itself: no compromised plugins, themes, or custom code. As far as I could find, with an estimated 500 million+ websites running the platform, WordPress has decided to push the update rather aggressively.
If, for any reason, you cannot update right away, wp2shell (also the name given to the vulnerability) can probe your live site and tell you whether it is exposed. It comes from Searchlight Cyber, the team that found the bug. The same page offers mitigations without updating the system core. However, all the listed methods, at the time of writing, carry some risk of breaking other functionalities, and the measures themselves are temporary by design.
I understand there is now an actual demand for simpler (i.e. modernist) websites and blogs, and to that crowd, WordPress is considered too heavy. I am in a boat where I prefer to run WordPress leaner by disabling unused features, rather than actually hosting a website on an untested platform. But if your website is static enough, I suppose looking into alternatives could be worthwhile.
