
What is wp2shell and what can it teach us about vulnerability management?
When wp2shell hit WordPress Core, no single check was enough. A look at how a WAF rule can make vulnerable servers appear patched, and why we shipped three checks instead of one.
Benjamin Marr
min read
July 21, 2026
min read
See TODAY’S CVE TRENDS
Our latest research
Subscribe to the
Vulnerabulletin
Vulnerabulletin
Our reports

The Security Middle Child
How midmarket security teams are managing growth, complexity, and risk
get the report
Cyber explainers
Product news
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.













