Vulnerable plugins
Outdated plugins are the single most common way WordPress sites get hacked — each one can carry a publicly documented vulnerability.
What it is
WordPress's power comes from plugins, but every plugin is extra code running on your site, written by someone else. When a security flaw is found in a plugin, it's published as a CVE — a public vulnerability record — and a fixed version is released.
Sites that don't update stay vulnerable to a flaw whose details are now public knowledge, including exactly how to exploit it.
Why it matters
The overwhelming majority of hacked WordPress sites are compromised through a known, already-patched plugin vulnerability. Because the flaws are documented publicly, attackers automate scanning for them at scale. An outdated plugin with a critical CVE is one of the most direct routes to a full site takeover.
How Pentrawl checks it
Pentrawl detects plugins referenced in your page source and their versions where available, then checks them against a list of plugins with known CVEs. A vulnerable version is flagged as a critical issue.
How to fix it
Keep every plugin updated, remove any you no longer use, and update immediately when a security release is published. Enabling automatic updates for plugins is the safest default for most sites.
Update all plugins to their latest version and enable automatic updates where possible.