Advising you to move to their own system then advising that you can't embed images into posts is laughable. Core WordPress is very secure and whilst it may not be ideal for every use case, and there are a lot of vulnerable plugins out there, that really only reflects the sheer size of the installed base - millions of websites and thousands of plugins.
In fact I'd suggest moving to their own system would be *less* secure, unless they're saying they have more knowledge, expertise and testing capability than the collective open source community.
Keep the site updated, install a plugin like Wordfence, and use either Cloudflare or a host with decent mod_security filtering (ideally Imunify360) and you'll be as secure as you can be.