Quick Response Foils Potential Website Threat
The college’s website and SUNY Niagara Today website may have been targeted last week through what website experts are calling the “wp2shell vulnerability.” In plain language, the wp2shell vulnerability is a bug that can be used to gain unauthorized administrative access to many websites build, as the college’ is, using the WordPress platform.
There is no evidence that any SUNY Niagara web asset was breached. However, recognizing the value of transparency about such events, the PR office wants the campus community to know what happened:
- On July 17, WordPress discovered the wp2shell vulnerability and released a new version of its platform to patch it. Both the www.sunyniagara.edu and SUNY Niagara Today are built using WordPress.
- By 21 July, Pantheon, the company that hosts the college’s website, and Northern, the firm that responds to critical website incidents on the college’s behalf, completed patch installation on www.sunyniagara.edu.
- On July 23, Matt Gagliardi completed patch installation on SUNY Niagara Today. He identified and deleted two unauthorized administrative SUNY Niagara Today accounts. Neither account appears to have gained access to SUNY Niagara Today.
The investment in enhanced website security that the PR office made as part of the 2023–2024 website redesign worked as intended. That’s the good news.
The bad news is that while the wp2shell vulnerability did not harm SUNY Niagara, the college probably will face more attacks like this. WordPress is an extremely popular website platform. In fact, there are between 472 million and 595 million WordPress websites worldwide. This makes it a high-value target for hackers.