Photo by Deng Xiang on Unsplash
If you still think you have a 48-hour window to patch a core vulnerability before the bots find you, you are living in 2012. The reality of the modern web is that the gap between a security announcement and an active exploit has narrowed to the point of being negligible.
Last week, WordPress pushed its second security release in less than a week. Version 7.1.2 was shipped to address a path traversal flaw that allowed for remote code execution. According to a report from WebHosting.Today, hackers were already hitting the exploit before the sun had set on the day of the release. This wasn't a slow burn; it was an immediate, automated pursuit of every unpatched site on the grid.
The infrastructure is the firewall
For twenty years, I’ve watched the industry shift from 'manual updates' to 'forced auto-updates,' yet we still see massive compromise events. Why? Because the nuance of this specific flaw depended heavily on the theme architecture and how the hosting environment was hardened. This highlights a fundamental truth: a CMS is only as secure as the house it sits in. If your host isn't layering protection at the edge, you are essentially relying on a race between a developer's patch and a bot's script. The bot usually wins.
We are seeing the commoditization of exploits. The moment a fix is committed to a public repository, it is reverse-engineered and fed into scanning clusters. For hosting providers, this means that 'managed services' can no longer just be about keeping the lights on. It has to be about proactive WAF rules and virtual patching that happens minutes after a CVE is logged, not days.
It is almost impressive that we have reached a point where hackers have better CI/CD pipelines for their exploits than most small businesses have for their actual websites.
Speed is the only metric
The lesson here isn't just that you need to update; it's that you need to be with a provider that treats security as a race they intend to win. If you’re still waiting for a weekly maintenance window to apply security patches, you aren't running a website—you're hosting a target.