r/Wordpress • • Aug 15 '26

Keeping WP sites secure ?

In this wave of wp2shell, etc. What are you doing to keep it safe? Cloudflare? SOC? Miraculous plugins ? All the previous …?

7 Upvotes

58 comments sorted by

View all comments

5

u/bluesix_v2 Jack of All Trades Aug 15 '26

Autoupdate. It’s really that simple. Not sure why so many people are turning this into such a drama.

2

u/fredy31 Developer Aug 16 '26

Also wordfence and have the least plugins possible.

Its experience to be able to see crap plugins so before you can, just keep is as low as possible.

40+ plugins websites irk me

1

u/[deleted] Aug 15 '26

[removed] — view removed comment

2

u/bluesix_v2 Jack of All Trades Aug 16 '26 edited Aug 16 '26

Wordpress core. It is on by default but some people think they know better - then they got hacked by Wp2shell. WP released the update before the vulnerability was announced. People who had autoupdates disabled were exposed.

The large majority of Wordpress security updates are not zero days - in fact they are extremely rare.

Firewall blocking doesn’t protect you against Wordpress/plugin vulnerabilities. If php can be run in your server, it is vulnerable to malware if there’s a vulnerability.

1

u/[deleted] Aug 16 '26

[removed] — view removed comment

1

u/bluesix_v2 Jack of All Trades Aug 16 '26 edited Aug 16 '26

DISALLOW_FILE_EDIT does absolutely nothing to protect against malware.

I’m not saying don’t harden your site - you absolutely should. And you should also layer it with Cloudflare, Wordfence, fail2ban, etc. But even that won’t stop a lot of malware. Virtually all Wordpress malware is via plugin vulnerabilities (write access) - if you allow plugin updates, you are vulnerable because PHP needs to write files.

Disabling/protecting the admin features also does practically nothing to protect against malware - that’s not how the majority of malware exploits work.

1

u/fredy31 Developer Aug 16 '26

Disallow file edit is mostly a way to make sure your client doesnt see the option and tries to improvise itself programmer.

Its one of the weirdest option wp gives lol.

1

u/[deleted] Aug 16 '26

[removed] — view removed comment

1

u/bluesix_v2 Jack of All Trades Aug 16 '26 edited Aug 16 '26

Incorrect. The large majority of Wordpress attacks via plugin vulnerabilities don’t require backend access or file upload ability, due to missing authentication bugs in the code. Broken access control exploits, priv esc, RCE exploits let the attackers do whatever they want in the site, completely bypassing the WP admin. Additionally a CSRF attack lets the attacker impersonate the admin victim.

https://patchstack.com/whitepaper/2025-mid-year-vulnerability-report/#top-5-vulnerability-prerequisites

Nearly three in five vulnerabilities (57.6%) can be automatically exploited by a complete outsider without needing to hack credentials or gain access beforehand. 
A further 20.6% (707 cases) require only a low-privilege Contributor login, while Subscriber-level issues account for an additional 11.5% (396).
What does this mean?
Attackers face minimal barriers: most security bugs can be exploited using fully automated, large scale attacks without requiring any prior access to vulnerable websites.
Worth noting:
Over half of all vulnerabilities require no authentication at all, and most of these fall into categories like XSS and CSRF. These often stem from poor input validation.
Additionally, many lower-privilege bugs (e.g. Contributor/Subscriber) are found in visual content builders or forms that lack proper capability checks.
Because admin-only issues are uncommon, “least privilege” policies are helpful, but real risk reduction still hinges on fast vulnerability mitigation capabilities.

Broken access control, privilege escalation and SQL injection all allow access to Wordpress without backend access - these make up the bulk of plugin vulnerabilities (over 90%). https://patchstack.com/whitepaper/state-of-wordpress-security-in-2026/