Plugin Security Red Flags and Safer WordPress Updates Guide
Weekly WordPress security roundup: key plugin and theme vulnerabilities, risk scores, and update guide to reduce threats across your sites.
Continue Reading
Critical WordPress Plugin Risks & Smarter Spam Defence
Vulnerable WordPress plugins span critical to medium risk this week, some with no fix. Our guide shows how to lock spam out of your forms.
Continue Reading →
OMGF Pro, Elementor, MainWP & More; Spot the Biggest WordPress Threats
Critical 10/10 security risk in OMGF Pro, with others like Elementor and MainWP also flagged. Spot the biggest WordPress threats and learn what to do next.
Continue Reading →
WordPress Plugin Vulnerabilities & the Hidden OptinMonster CDN Attack: Detect What Others Miss
Critical WordPress vulnerabilities, the OptinMonster CDN supply chain attack, and how Shield uncovers the malware that traditional security tools can't detect.
Continue Reading →
Why the OptinMonster CDN Attack Is a Case for On-Site WordPress Security
On 12 June 2026, a compromised CDN credential turned OptinMonster and TrustPulse into malware delivery vehicles targeting WordPress admins. Cloudflare couldn't stop it. A WAF couldn't stop it. We look at why on-site WordPress security is the layer that actually matters here, and what Shield is building next to catch an attack technique most security tools can't even see.
Continue Reading →
20 Critical WordPress Vulnerabilities to Fix This Week
New WordPress plugin and theme vulnerabilities this week. Check the top risks, severity scores, fixes, and hardening solutions to keep your site secure.
Continue Reading →
OttoKit, WPvivid, Blocksy, and More WordPress Vulnerabilities & Lock Down App Permissions
Fresh WordPress plugin and theme vulnerabilities landed this week, some critically severe. Time to update, and time to restrict your connected tool access.
Continue Reading →
Introducing Mandate App Security – Scope What Your Connected Tools Can Do in WordPress
Mandate App Security is a new WordPress plugin that narrows what a connected tool can do after it authenticates with an Application Password. You choose which capabilities to allow, and Mandate enforces that scope on every request the password makes. It's built for sites connecting to AI tools, automation platforms, REST API clients, and MCP connectors.
Continue Reading →
No Rest for WordPress: ACF Extended Critical & A Notice From Shield’s Team
ACF Extended joins the list of critically vulnerable WordPress plugins, and Shield Security is ending PHP 7.4 support. Here is what you need to know.
Continue Reading →
Why Shield Security is Dropping PHP 7.4 Support
PHP 7.4 has been without a security patch since November 2022, and the consequences are now catching up with plugins that depend on it. Shield Security's next major release will require PHP 8.2 as a minimum. Here's why the change is necessary and what you need to do before it arrives.
Continue Reading →