
How to find and fix vulnerable WordPress plugins?
- Sajjad
- WordPress, Security
- 13 Sep, 2026
To find vulnerable WordPress plugins, run a vulnerability scan with a tool like Wordfence, Patchstack, Jetpack Protect, or Solid Security, or compare your installed plugin versions against a database such as Wordfence Intelligence or WPScan. To fix them, update to the patched version as soon as it's available. If no fix exists, apply a virtual patch through a firewall, switch to a maintained alternative, or deactivate and delete the plugin until it's safe.
Outdated and vulnerable plugins are the most common entry point for attackers targeting WordPress sites. The good news is that most of these attacks are preventable with a simple routine: know what you have installed, know when it's vulnerable, and act quickly. This guide walks through how to identify vulnerable plugins, how to prioritize them, and how to fix each situation safely.
Why Vulnerable Plugins Are a Big Risk
When a vulnerability in a popular plugin is publicly disclosed, attackers often start scanning the web for affected sites within hours or days. Automated bots don't care how small your site is. They simply look for the vulnerable plugin version and try the exploit.
Common plugin vulnerability types include:
- Cross-site scripting (XSS): Lets attackers inject JavaScript that runs in visitors' or admins' browsers.
- SQL injection: Lets attackers read or modify your database.
- Broken access control: Missing capability or nonce checks let low-privileged users, or even logged-out visitors, perform admin actions.
- Arbitrary file upload: Lets attackers upload a PHP file and run it on your server.
- Privilege escalation: Lets a subscriber become an administrator.
- Remote code execution: The most serious type, allowing attackers to run arbitrary code.
The severity and exploitability vary a lot. A vulnerability that requires an administrator account is far less urgent than one that any visitor can trigger.
Step 1: Get a Complete Inventory of Your Plugins
You can't secure what you don't know about. Start by listing every plugin, including inactive ones.
In the dashboard, go to Plugins > Installed Plugins and review both active and inactive plugins. Don't forget:
- Must-use plugins: Listed under the Must-Use tab if present. These load automatically from
wp-content/mu-plugins. - Drop-ins: Files like
object-cache.phporadvanced-cache.phpinwp-content. - Bundled plugins: Some themes bundle plugins like sliders or page builders that may not update through the normal system.
With WP-CLI, you can get a full list with versions and update status:
wp plugin list --fields=name,status,version,update,update_version,auto_update --format=table
On a multisite network, add --url for a specific site, or check network-activated plugins with wp plugin list --status=active-network.
Step 2: Scan for Known Vulnerabilities
Use a Security Plugin
Several security plugins check your installed plugin versions against vulnerability databases and alert you when something is affected:
- Wordfence: Its scan flags plugins with known vulnerabilities and plugins that have been removed from WordPress.org.
- Patchstack: Specializes in vulnerability monitoring, with alerts and optional virtual patching on paid plans.
- Jetpack Protect: Free vulnerability scanning using the WPScan database.
- Solid Security: Its Site Scan checks for known vulnerabilities in your plugins, themes, and core.
Install one of these (you don't need all of them), run a scan, and review the results.
Check Vulnerability Databases Manually
For a specific plugin, you can search public databases directly:
- Wordfence Intelligence: Free, detailed vulnerability records.
- Patchstack Database: Includes severity scores and patched versions.
- WPScan Vulnerability Database: Widely used by other tools.
Each record typically shows the affected versions, the fixed version, a severity score (often based on CVSS), and a short description.
Use the WPScan CLI for Your Own Sites
If you manage your own sites and are comfortable on the command line, the WPScan CLI tool can check which plugin versions are exposed and compare them against the WPScan database. You need a free API token from WPScan for vulnerability data. Only scan sites you own or have written permission to test.
# Install via RubyGems
gem install wpscan
# Enumerate vulnerable plugins on your own site
wpscan --url https://example.com --enumerate vp --api-token YOUR_API_TOKEN
Because WPScan works from the outside, it may not detect every plugin. Server-side tools inside WordPress are more complete.
Step 3: Prioritize What to Fix First
If a scan reports several issues, don't panic. Prioritize based on real risk.
- Unauthenticated, high-severity issues: Vulnerabilities that logged-out visitors can exploit, such as file upload or SQL injection, are the most urgent. Fix these immediately.
- Actively exploited vulnerabilities: If security vendors report active exploitation, move it to the top of the list.
- Low-privilege authenticated issues: If your site allows open registration, a subscriber-level vulnerability is effectively public.
- Admin-only issues: Vulnerabilities that require an administrator account are lower priority on sites with few trusted admins, but still worth fixing.
- Inactive plugins: Even inactive plugins can be exploitable if their files are accessed directly. Delete them rather than leaving them deactivated.
Step 4: Fix by Updating
In most cases, the fix is simple: update the plugin to a version that includes the patch.
- Back up first: Take a full backup of files and database, or confirm your host's recent backup is available.
- Read the changelog: Check the plugin's changelog for breaking changes, particularly with major version jumps.
- Update on staging if possible: For complex sites or stores, test the update on a staging copy first.
- Update on production: Go to Dashboard > Updates or Plugins > Installed Plugins and click Update now.
- Test your site: Check key pages, forms, checkout, and admin functions.
- Rescan: Confirm the vulnerability no longer appears.
With WP-CLI, updating a specific plugin or all plugins looks like this:
# Update one plugin
wp plugin update contact-form-7
# Update all plugins with available updates
wp plugin update --all
# Preview what would be updated
wp plugin update --all --dry-run
For urgent security updates, it's usually better to update quickly and fix minor issues afterwards than to leave a known vulnerability exposed while you wait for a perfect testing window.
Enable Auto-Updates for Trusted Plugins
WordPress supports automatic plugin updates. On the Plugins screen, click Enable auto-updates next to each plugin you trust. This works well for small, well-maintained plugins and security plugins. For complex plugins like page builders or WooCommerce extensions, you may prefer manual updates with testing.
You can also enable auto-updates via WP-CLI:
wp plugin auto-updates enable wordfence
Step 5: Fix When No Update Is Available
Sometimes a vulnerability is disclosed before the developer releases a fix, or the plugin is abandoned. Here's what to do.
Option A: Apply a Virtual Patch
A virtual patch is a firewall rule that blocks attempts to exploit a specific vulnerability without changing the plugin's code.
- Patchstack: Paid plans deploy targeted virtual patches for many known vulnerabilities.
- Wordfence Premium: Receives real-time firewall rules that often cover newly disclosed vulnerabilities. Free users get the same rules after a delay.
- Cloud WAFs: Sucuri and Cloudflare's managed rules can block some known exploits.
Virtual patching buys you time, but it isn't a permanent fix. Plan to update or replace the plugin.
Option B: Replace the Plugin
If the plugin is abandoned or the developer isn't responding, find a maintained alternative:
- Look for a plugin that offers the same features, with recent updates and a good security record.
- Test the replacement on staging.
- Migrate settings and content. Some plugins offer import tools.
- Deactivate and delete the vulnerable plugin once the replacement works.
Option C: Deactivate and Delete
If the plugin isn't essential, removing it is the safest option. Deleting a plugin removes its files, which eliminates the vulnerable code.
wp plugin deactivate old-slider-plugin
wp plugin delete old-slider-plugin
Check whether the plugin left database tables or options behind. Some plugins clean up on uninstall, while others leave data you can remove manually after a backup.
Option D: Temporary Mitigation
If you absolutely must keep a vulnerable plugin running for a short time, reduce exposure:
- Block access to the vulnerable endpoint, such as a specific AJAX action or file path, using your firewall or server rules.
- Disable open registration if the vulnerability requires a subscriber account.
- Restrict access to the affected feature by IP.
For example, if a vulnerability affects a directly accessible PHP file inside a plugin folder, you could block it on Apache 2.4 with an .htaccess file placed in that plugin's directory:
<Files "vulnerable-file.php">
Require all denied
</Files>
Or on Nginx, inside your server block:
location = /wp-content/plugins/example-plugin/vulnerable-file.php {
deny all;
}
These are stopgaps. Remove them once the plugin is updated or replaced.
Step 6: Check Whether You Were Already Compromised
If a plugin was vulnerable for a while before you fixed it, check whether an attacker exploited it before you patched.
- Run a malware scan: Use Wordfence, MalCare, or a similar scanner.
- Look for new admin users: Review Users > All Users filtered by Administrator.
- Check for unexpected files: Especially PHP files in
wp-content/uploads. - Review activity logs: Look for suspicious logins, role changes, or plugin installations around the time the vulnerability was disclosed.
- Verify file integrity: Run
wp core verify-checksumsandwp plugin verify-checksums --all.
If you find signs of compromise, follow a full cleanup process, and see our guide on recovering a hacked WordPress site.
Step 7: Build a Routine to Stay Ahead
Fixing one vulnerability is good. Preventing the next one from becoming a problem is better.
- Enable vulnerability alerts: Keep one alerting tool active so you hear about issues quickly.
- Check for updates at least weekly: Or enable auto-updates for low-risk plugins.
- Remove unused plugins every quarter: Fewer plugins mean fewer vulnerabilities.
- Keep a staging site ready: So testing updates is quick when a critical fix arrives.
- Keep WordPress core and PHP updated: Many plugin vulnerabilities are harder to exploit on current software.
- Follow security news: Wordfence, Patchstack, and WPScan publish regular vulnerability reports.
A Simple Weekly Check With WP-CLI
If you manage several sites, a short script can show available updates across them. Here's a simple example you could run on a server hosting multiple WordPress installs:
#!/usr/bin/env bash
# List plugins with available updates for each site
for site in /var/www/*/public_html; do
if [ -f "$site/wp-config.php" ]; then
echo "== $site =="
wp --path="$site" plugin list --update=available --fields=name,version,update_version --format=table
fi
done
Run it as the user that owns the WordPress files rather than root. If you must run as root, add --allow-root, but it's better to avoid that.
FAQ: Vulnerable WordPress Plugins
Run a vulnerability scan with Wordfence, Patchstack, Jetpack Protect, or Solid Security, or search your installed plugins in Wordfence Intelligence, Patchstack, or WPScan. These tools compare your versions against known vulnerabilities.
Apply a virtual patch through a firewall like Patchstack or Wordfence Premium, replace the plugin with a maintained alternative, or deactivate and delete it until a fix is available.
They can be. Deactivated plugins still have files on your server, and some vulnerabilities can be triggered by accessing those files directly. Delete plugins you don't use.
For well-maintained, low-risk plugins, auto-updates are a good way to get security fixes quickly. For complex plugins like page builders or WooCommerce extensions, you may prefer to test updates on staging first.
As soon as possible, ideally within a day for high-severity unauthenticated vulnerabilities. Attackers often start scanning for newly disclosed vulnerabilities within hours or days.
A virtual patch is a firewall rule that blocks attempts to exploit a specific vulnerability without changing the plugin's code. It protects you until a proper update is installed.
Occasionally, especially with major version changes. Taking a backup and testing on staging reduces the risk, and most security updates are small, focused fixes.
Conclusion
Finding and fixing vulnerable WordPress plugins is a routine task, not a crisis, when you have the right process. Keep a complete inventory, use a vulnerability scanner or database to spot problems, and prioritize issues that visitors can exploit without logging in. In most cases, updating to the patched version is all it takes.
When there's no fix, a virtual patch, a replacement plugin, or simply deleting the plugin keeps your site safe. After fixing a vulnerability, check that it wasn't exploited in the meantime, and build a weekly habit of reviewing updates and alerts. Staying a step ahead of plugin vulnerabilities is one of the most effective things you can do for your site's security.


