What to do when a WordPress plugin you use has a security vulnerability

A step-by-step guide to handling a security vulnerability in a WordPress plugin or theme you use: checking whether you are affected, updating safely, what to do if there is no fix and how to check whether your site was attacked.

Security problems in WordPress plugins are found every week. Most get fixed quietly in an update before anyone attacks them. A few are serious, get fixed after attackers have already found them, or don't get fixed at all. When you hear that a plugin on your site has a vulnerability, whether from a news story, a security plugin alert, your host or our weekly This week in WordPress roundup, the question is always the same: do I need to do anything, and how quickly?

This guide walks through the steps in order. For most vulnerabilities it takes five minutes and ends with an update. The later sections cover what to do when it's more serious than that.

Check whether you're actually affected

Start by confirming three things.

Do you have the plugin? Go to Plugins → Installed Plugins and search for it. Some plugins are bundled inside themes (sliders and page builders especially) and may not appear under their usual name. If a vulnerability affects a theme, check Appearance → Themes.

Is your version affected? The plugin list shows the version you're running. Vulnerability reports say which versions are affected and which version contains the fix, usually in the form "versions up to and including 3.4.1, fixed in 3.4.2". If you're already on the fixed version or later, you're done.

Is the plugin active? An inactive plugin is much less risky, but not always safe. Some vulnerabilities can be reached by requesting the plugin's files directly, whether or not it's switched on. If you're not using it, take a backup and then delete it rather than leaving it deactivated.

Work out how urgent it is

Not every vulnerability needs dropping everything for. The reports usually tell you enough to decide.

Is it being actively exploited? If security companies are reporting attacks in the wild, update today. Automated attacks scan huge numbers of sites for vulnerable plugins soon after a working attack becomes known.

Who can use it? Reports will say whether an attacker needs to be logged in, and at what level. A vulnerability that anyone can use without logging in is the most urgent kind. One that needs an administrator account is much less of a worry. In between are vulnerabilities that need a "subscriber" or "customer" account. Don't dismiss those if your site lets people register. Every WooCommerce customer with an account is a logged-in user, so on a shop, "requires subscriber-level access" can mean "anyone who has ever bought something".

How severe is it? Reports label vulnerabilities as critical, high, medium or low. Critical and high issues that don't need a login deserve attention the same day. Low-severity issues that need admin access can wait for your next routine update.

Update the plugin

For most vulnerabilities, updating is the whole fix.

  1. Take a backup. If your host offers one-click backups or snapshots, that's usually the quickest option.
  2. Go to Plugins → Installed Plugins or Dashboard → Updates and update the plugin.
  3. Check that the version number now matches or exceeds the fixed version.
  4. Check the important parts of your site still work: the homepage, contact forms and, for shops, adding to basket and checking out.

If the update breaks something, our guide to recovering a site broken by an update explains how to roll back safely. Rolling back puts the vulnerability back, though, so treat it as a short-term measure while you get the problem fixed. If the update leaves the site showing "Briefly unavailable for scheduled maintenance", see our guide to getting WordPress out of maintenance mode.

Premium plugins with expired licences

Premium plugins usually only update through the dashboard while your licence is active. If the licence has lapsed, WordPress may not even tell you an update exists. Log into your account on the plugin developer's website, where you can often still download the latest version, or renew the licence. If you bought the plugin as part of a theme, check whether the theme developer has released an update that includes the fixed version.

Installing a downloaded copy over the top of the existing plugin replaces its files, so take a backup first.

If there's no fix yet

Sometimes a vulnerability is made public before the developer has released an update, or the developer has stopped maintaining the plugin altogether. WordPress.org often closes plugins in this situation, and our guide to dealing with closed or abandoned plugins covers that in more detail.

Your options, in rough order of preference:

  • Deactivate and delete the plugin if you can live without it for a while. This is the only option that fully removes the risk. Deleting a plugin can also delete its settings and data, so take a backup first.
  • Replace it with a maintained alternative that does the same job.
  • Turn off the vulnerable feature, if the report says the problem is limited to one part of the plugin that you don't use. This is only a partial measure, since the code is still on your site.
  • Use a firewall with virtual patching. Some security services, such as Patchstack, write firewall rules that block attacks on a specific vulnerability before the plugin itself is fixed.1 This buys you time, but it isn't a substitute for updating or removing the plugin.

Check whether your site was attacked

If the vulnerability was being actively exploited and your site was running an affected version, check for signs of compromise, even after updating. Updating closes the door, but it doesn't remove anything an attacker may have left behind.

Things to look for:

  • Unfamiliar administrator accounts. Go to Users and filter by Administrator. Attackers very often create a new admin so they can get back in.
  • Plugins you didn't install, including ones with generic names. Check the must-use plugins list too, which appears on the Plugins screen if any exist.
  • Changes you didn't make to pages, menus, widgets or site settings, especially links to gambling, pharmacy or crypto sites.
  • Unexpected redirects, particularly ones that only happen on mobile, for first-time visitors or when arriving from Google.
  • A security scan with a security plugin or a remote scanner such as Sucuri SiteCheck. These won't catch everything, but they'll catch the common stuff.
  • Your server access logs, if the vulnerability report mentions a specific file or URL used in attacks. Your host can help you search for it.
  • Sudden load or errors. Heavy automated attack traffic can cause 502, 503 or 504 errors or a suddenly slow site.

If you find anything, don't start deleting files straight away. Take a backup of the site as it is now, since it's evidence of what happened, then follow our guide to cleaning up a hacked WordPress site. Change all admin passwords. If the attack could have exposed customer data, you may have legal obligations to report it, which is outside the scope of this guide. The data breach section of our hacked site guide points to where to find guidance, and you should take appropriate advice promptly.

Make the next one easier

Every WordPress site will face this again, so a few habits make the next time quicker and less stressful.

  • Turn on automatic updates for plugins you trust. Since WordPress 5.5 you can enable them per plugin from the Plugins screen.2 Most security fixes then install themselves soon after release. Pair this with regular automatic backups, so an update that goes wrong is easy to undo.
  • Remove plugins you don't use. Every installed plugin is something that can have a vulnerability, active or not.
  • Keep premium licences active for any plugin that matters to your site, so security updates keep arriving.
  • Keep an eye on security news. Our weekly This week in WordPress roundup lists the plugin security updates that matter each week, in plain English, with what to do about each one.
  • Keep regular off-site backups, so a worst case is a restore rather than a rebuild.

Need help?

If you're not sure whether a vulnerability affects your site, or you think your site may already have been attacked, my emergency WordPress support can check and clean it up. If you'd rather someone else kept an eye on updates and security notices for you, my WordPress maintenance plans cover exactly that.

Adam Greenough

Written by Adam Greenough

Freelance web developer with over 15 years of experience building and fixing WordPress sites. I work with businesses across the UK on everything from emergency support to full builds.

Need emergency WordPress support today?

If your site is down, hacked or throwing errors, send me the details and I will assess the problem quickly. Support starts from £50, you will get a fixed quote before any work begins, and if I cannot fix the issue, you will not pay.