OttoKit, WPvivid, Blocksy, and More WordPress Vulnerabilities & Lock Down App Permissions
Fresh WordPress plugin and theme vulnerabilities landed this week, some critically severe. Time to update, and time to restrict your connected tool access.
Continue Reading →
Introducing Mandate App Security – Scope What Your Connected Tools Can Do in WordPress
Mandate App Security is a new WordPress plugin that narrows what a connected tool can do after it authenticates with an Application Password. You choose which capabilities to allow, and Mandate enforces that scope on every request the password makes. It's built for sites connecting to AI tools, automation platforms, REST API clients, and MCP connectors.
Continue Reading →
No Rest for WordPress: ACF Extended Critical & A Notice From Shield’s Team
ACF Extended joins the list of critically vulnerable WordPress plugins, and Shield Security is ending PHP 7.4 support. Here is what you need to know.
Continue Reading →
Why Shield Security is Dropping PHP 7.4 Support
PHP 7.4 has been without a security patch since November 2022, and the consequences are now catching up with plugins that depend on it. Shield Security's next major release will require PHP 8.2 as a minimum. Here's why the change is necessary and what you need to do before it arrives.
Continue Reading →
High BookingPress Pro Risk, npm Attacks, and WordPress Breach Recovery
High BookingPress Pro flaws, npm supply chain attacks, and active plugin exploits put WordPress sites at risk. See affected plugins and breach recovery tips.
Continue Reading →
WP Shield Security PRO – Release 22.0
ShieldPRO 22.0 is one of our most ambitious releases yet. It completely transforms your relationship with WordPress security by always guiding you towards the issues that need your most attention when you need it.
Continue Reading →
Critical WordPress Plugin Vulnerabilities: Burst Statistics & What Hardening Really Costs
20+ popular vulnerable WordPress plugins and themes this week. Burst Statistics critical flaw, security risks, and what hardening really costs.
Continue Reading →WordPress Security Breach Symptoms and 5-Step Recovery
Spot breach symptoms fast, follow a 5-step recovery plan, and prevent reinfection with automation that matches the exploit window.
Continue Reading →What WordPress Security Hardening Services Actually Cost
WordPress security hardening costs $120-149/yr for plugins, $150-500 one-time, or $30-150/mo managed. See real vendor prices & bundled vs separate TCO math.
Continue Reading →WordPress Security Hardening Services Complete Overview
WordPress hardening means exact file permissions (755/644), database privileges, 2FA setup, and isolated backups. Get specific settings and clear DIY guidance.
Continue Reading →