start in plugins and themes
Known weaknesses are the usual entry point.
Most WordPress hacks start at a known flaw in a plugin or theme. MalCare checks every version you run against 39,000+ tracked vulnerabilities daily, alarms you the day a flaw affects your site — and Vulnerability Shield covers it within hours, whether or not a patch exists.






Exploit scripts don't pick targets — they probe every site running the flawed version. Most owners learn about the flaw from the hack.
Known weaknesses are the usual entry point.
Attackers are moving faster after disclosure.
MalCare's alarm arrives on day zero instead.
Our security team reviews disclosures from 10+ sources every day — duplicates removed, conflicts resolved, every flaw re-scored for how it's actually exploitable.
| National databaseCVSS v3.1answers 2/6 | Exploit trackerin-the-wild feedanswers 4/6 | Vendor advisorynothing publishedanswers 0/6 | What the sources sayanswered 2 / 4 / 0 | MalCare verdictone entry, re-scoredanswers 6/6 | |
|---|---|---|---|---|---|
| Severity | High | Critical | no entry | High / Critical / — | Critical |
| Score | 7.5 | 9.8 | no entry | 7.5 / 9.8 / — | 9.8 |
| Needs a login | Not stated | No | no entry | Not stated / No / — | No |
| Exploit in the wild | Not tracked | Circulating | no entry | Not tracked / Circulating / — | Circulating |
| Vendor patch | no entry | Not tracked | no entry | — / Not tracked / — | None yetshield covers it |
| Affects your site | no entry | no entry | no entry | — / — / — | Yesversion 3.2 installed |
Without vulnerability data, updating is guesswork. The queue marks which updates are security-critical, so “now or later?” has an answer.
Two ways to close the exposure — shield it now, or update it safely. Each is one click.
Available immediately · no vendor needed
Your code is untouched.3.2 stays · covered in hours
When the vendor ships · 46% of flaws have none on day zero
Your code is replaced, and checked.3.3 installed · 0 visual differences
The shield holds until you update. The update is permanent.
Names the plugin, the version, and the verdict — with the reasons.
46% of flaws have no patch on disclosure day. A virtual patch covers yours within hours. How virtual patching works →
A Visual Regression Test compares your site before and after the update.
10+ sources, reviewed daily — deduplicated, conflict-resolved, and re-scored before anything reaches you.
Improper access control in form-builder-pro allows unauthorised modification of form submissions.
SeverityYour stack, checked daily against 39,000+ tracked vulnerabilities — the shield and the safe update one click away.