wp2shell: more than a month later. Confirm 6.8.6, 6.9.5, 7.0.2. Patched is not clean.

Read the advisory
Mentality Dictionary

Assume breach

Definition

Assume breach means designing as if an attacker may already have a foothold, so detection and recovery matter as much as prevention.

Also called: assume-breach

Why it matters for WordPress

Perfect prevention fails eventually: a zero-day plugin hole, a phished editor, a vendor compromise. Teams that only “lock the door” freeze when something slips through. Assume breach means you can still answer what changed, restore cleanly, and hunt persistence.

How it shows up in practice

  • A staging restore drill you actually ran last quarter
  • An events log that answers “who created that admin?”
  • Password and salt rotation as routine after incidents, not panic theater
  • A named person (or agency) who owns malware cleanup

What to do

  1. Practice a restore on staging before you need production heroics.
  2. Keep event logging and file integrity checks on.
  3. Write a one-page incident checklist while everyone is calm.
  4. After any compromise, hunt persistence. Do not only delete the weird file.

Nearby ideas in the dictionary

All terms →

Larger screenshot