You Patched wp2shell. Now Prove You Were Not Already Breached
Both wp2shell CVEs went into CISA's KEV catalog on 21 July and public exploits are circulating. Patching closed the door; it did not tell you whether anyone was already inside. A WP-CLI compromise-assessment runbook, and the line where cleanup stops and rebuild begins.