security / cms & plugins / vulnerable plugins
CMS & plugins

Vulnerable plugins

Outdated plugins are the single most common way WordPress sites get hacked — each one can carry a publicly documented vulnerability.

Severity if missing
Critical
Category
CMS & plugins
Standard
CVE

What it is

WordPress's power comes from plugins, but every plugin is extra code running on your site, written by someone else. When a security flaw is found in a plugin, it's published as a CVE — a public vulnerability record — and a fixed version is released.

Sites that don't update stay vulnerable to a flaw whose details are now public knowledge, including exactly how to exploit it.

Why it matters

The overwhelming majority of hacked WordPress sites are compromised through a known, already-patched plugin vulnerability. Because the flaws are documented publicly, attackers automate scanning for them at scale. An outdated plugin with a critical CVE is one of the most direct routes to a full site takeover.

The risk
A plugin with a known vulnerability can let attackers inject content, steal data or take over your site entirely — often through fully automated attacks.

How Pentrawl checks it

Pentrawl detects plugins referenced in your page source and their versions where available, then checks them against a list of plugins with known CVEs. A vulnerable version is flagged as a critical issue.

How to fix it

Keep every plugin updated, remove any you no longer use, and update immediately when a security release is published. Enabling automatic updates for plugins is the safest default for most sites.

Recommended
Update all plugins to their latest version and enable automatic updates where possible.
Check your domain's Vulnerable plugins in seconds
Pentrawl scans this and 20+ other security checks in one automated pass.
Scan your website →