BugShield scanned 100,000 WordPress sites for the Gravity Forms vulnerability
BugShield scanned 100,000 WordPress URLs and found 4,697 that appeared to run a vulnerable Gravity Forms version. Many were still on the older 2.x branch.
Read articleNew 24/7 monitoring and daily cloud backups now included in every Shield Pro plan.
Blog
Product updates, WordPress advice, and stories from behind the shield.
BugShield scanned 100,000 WordPress URLs and found 4,697 that appeared to run a vulnerable Gravity Forms version. Many were still on the older 2.x branch.
Read articleA critical WordPress page-template vulnerability is already being probed. Learn which sites meet the known conditions, how to update, and what to check.
Read articleWe removed the malicious files, but they returned from a payload hidden in the database. Here is how the persistence worked and why cleanup order mattered.
Read articleGravity Forms 3.1.0.4 and earlier contain a critical unauthenticated file upload vulnerability. Learn who is exposed, how to update, and what to check.
Read articleA customer thought their WordPress site was fine. Their first BugShield checks uncovered malware that had been sitting on the server for months.
Read articleElementor Pro 4.2.1 and earlier contain a critical file upload vulnerability under active attack. See who is exposed, what to check, and why you should update to 4.2.2.
Read articleAll-in-One WP Migration 7.109 and earlier contain a serious SQL injection vulnerability. Learn how the issue works and what WordPress site owners should do.
Read articleWishlist Member account takeover is an unauthenticated bug in WishList Member X through 3.34.1 via the mergewith parameter. See who is affected and what to do.
Read articleWordPress 7.0.4 patches CVE-2026-65640, an Author-level Postscript upload RCE when Imagick and Ghostscript are present. See who is affected and what to do.
Read articleA WordPress plugin supply chain attack hit BdThemes in August 2026. See which plugins were affected, how hidden admins were created, and how to check your site.
Read articleWordPress XSS2Shell (CVE-2026-64638) is a login XSS that can lead to RCE. See who is at risk, patched versions, and check your site with our free tool.
Read articleWordPress security is not only plugins and scans. Optional authenticator 2FA and Active Sessions help lock down the BugShield account that holds your sites and vault.
Read article