Exercise 2: Why This Chapter Names a Real OWASP Category, Not Just "Best Practice" — Possible Solution ==================================================================== WHAT A VAGUE "BEST PRACTICE" FRAMING WOULD LOOK LIKE ------------------------------ A vaguer version of this chapter's warning might simply say "it's a good idea to keep plugins updated" - true, but abstract, and easy to mentally file away as a nice-to-have rather than a genuine, concrete risk with real-world consequences. WHAT THIS CHAPTER SAYS INSTEAD ------------------------------ Per this chapter's own warn-box, "a neglected WordPress update... is a textbook, real-world instance of OWASP Top 10's own Vulnerable & Outdated Components category: known, publicly documented vulnerabilities in old software versions are actively, automatically scanned for and exploited across the web." This names a specific, already-documented category of real attack from an authoritative external source (the OWASP Top 10), rather than presenting the advice as this course's own invented caution. WHY THIS IS A MEANINGFULLY STRONGER CLAIM ------------------------------ Connecting the advice to a real, externally-recognized vulnerability category makes clear that this isn't a stylistic preference or an overly cautious suggestion - it's describing a documented, real-world attack pattern that security professionals across the industry already formally track and warn about. The risk isn't hypothetical or exaggerated for teaching purposes; it's the same category of real incident organizations genuinely experience. WHY THIS CONNECTS TO WORDPRESS SPECIFICALLY, NOT JUST SOFTWARE GENERALLY ------------------------------ Per this chapter, "WordPress's own huge market share, named back in WordPress Fundamentals 1, makes it a genuinely common, high-value target for exactly this kind of automated scanning." This adds a second, WordPress-specific reason the abstract OWASP category applies with unusual force here: WordPress's sheer popularity means automated attack tooling built specifically to scan for outdated WordPress plugins and themes genuinely exists and is genuinely used at scale, not merely a generic risk that applies equally to every piece of software everywhere. WHY THIS WORKS AS AN ANSWER ------------------------------ It contrasts the actual chapter framing against a hypothetical vaguer "best practice" version, explains why citing a real, external, documented vulnerability category is a stronger and more credible claim than an abstract recommendation, and connects the specific WordPress market-share point that makes this risk concretely, not just theoretically, relevant.