WP2Shell was a warning: 4 tips to keep your WordPress site secure

In July 2026, cybersecurity researchers discovered a vulnerability chain in the WordPress core called WP2Shell: one of the most serious cybersecurity incidents in recent years. Two separate, already fairly serious vulnerabilities combined to give an attacker the ability to run any code on the site without any login. No username, no password, just an outdated WordPress installation was enough.

The fix was released already on Friday, July 17th. By the following Sunday, large-scale exploitation was in full swing around the world, including in Finland. In less than 48 hours, every unupdated site was thus fundamentally vulnerable to an attack. Many of the attacked websites still had a so-called backdoor even after the original vulnerability was patched, which allowed the attacker to return to the site later.

The lesson is clear: exploitation now begins in hours, not days or weeks. Monthly, carefully managed maintenance is no longer a nice-to-have, but a prerequisite.

What should regular WordPress site maintenance include?

  • The core, themes, and plugins are kept up to date, and unnecessary ones are completely removed. The core of WordPress, active themes, and all installed plugins are updated regularly. Equally important is to go through all installed plugins and remove those that are no longer used or that the manufacturer no longer updates. These “abandoned” plugins are one of the most common ways attackers gain access – in the case of WP2Shell, the issue was not with any extra plugin, but with the WordPress core itself, which serves as a reminder that even a basic installation is never automatically secure.
  • A regular backup of the site is taken and stored outside the site. It’s advisable to take a backup before major updates, and also at regular intervals otherwise. The backup must be stored elsewhere than on the server itself, because if the site is compromised, a backup on the same server won’t help at all. It’s also advisable to regularly test the functionality of the backup, not just when it’s actually needed.
    The site and its logs are checked for security purposes. This includes malware scanning, reviewing logins and user accounts (including the removal of old, unused accounts), ensuring the validity of the SSL certificate, and monitoring logs for anomalous activity. In attacks like the WP2Shell case, attackers often leave traces, such as unexpected new administrator credentials or unusual files on the server, which are only noticed if someone actually checks the logs regularly and not just when a problem arises.
  • The functionality of the site is tested after updates. An update can quietly break a function that no one notices until a customer tries to submit a contact form or complete a purchase at checkout. That’s why it’s worth reviewing key functions, such as forms, login, and the entire checkout process in online stores, after each update cycle. At the same time, it’s a good opportunity to check the site’s speed, broken links, and ensure that the content (contact information, prices, opening hours) is up to date – seemingly small things that affect both user experience and search engine visibility.

Cybersecurity is now more critical than ever

Cases like WP2Shell are not exceptions, but rather the direction we are heading in. When exploitation begins in hours rather than days, monthly, carefully managed maintenance is no longer a “nice to have” but a fundamental requirement for keeping the site up and customer data secure.

Wannado will take care of the monthly maintenance of your WordPress site for you: updates, backups, and security checks, at a flexible hourly rate of €75. Most of the time, this means 1–2 hours of work per month per site – no big, binding contract, just regular maintenance when it’s needed.

Do you need monthly maintenance for your WordPress site? Contact us, and let’s see what your site specifically needs. 💜

Leave a comment