Not on all shared hosting plans. And migrating from a shared hosting plan can be quite a lot of work, depending on the website.
Also: Getting a LetsEncrypt wildcard cert for Apache on a CentOS 8 VPS is non trivial (for individuals not already familiar with docker) [1]
Use the nginx/apache plugin, or the webroot option. Yes, it won't do *, but on shared hosting, that might even be better.
It seems crazy to me that Microsoft shops are annoyed that the Windows tooling for Let's Encrypt isn't great yet didn't direct that straight at their vendor. What's the point of having that relationship if they don't do what you need? Are you paying them because you hate money?
Microsoft definitely could, if the feedback from customers was there, have shipped an ACME client for IIS in newer IIS releases/ updates. But the feedback from customers is seemingly "More beatings please, and have you thought of increasing prices?"
1. Use CNAME to make different DNS server hierarchy own the ACME proof of control. A CNAME DNS record can be permanently added to your real site, telling Let's Encrypt that it should ask DNS for a different name instead, and only that name needs to be writeable by the periodic renewal process. You can use this to pass DNS challenges for a domain where actual DNS changes take six weeks and a dozen people's signatures, because you only need one change once, not once per renewal. You should find documentation explaining this, or you can ask Let's Encrypt's community site to help if you explain your specific situation.
2. CSR re-use. Certificate Signing Requests don't have timestamps inside them. By default Let's Encrypt's popular Certbot client mints brand new key pairs for every renewal and so it needs fresh CSRs, but you needn't do that. Mint keys once when a server is created, produce a CSR for the certificate you'll want, and then re-use that CSR in a machine which just does the renewal periodically, the actual servers can fetch their renewed certificate from that machine or wherever, the certificate is public so it doesn't matter and the keys haven't changed they just need the renewed certificate for the same keys.
CF also allows for self-signed certs: https://blog.cloudflare.com/origin-server-connection-securit... - which are (to me) more complicated than standard certs.
The real game changer in all of this is LetsEncrypt which has become the defacto option for services with huge amounts of custom domains (Shopify, Hubspot, Wordpress) etc.