Plugin vulnerabilities

Is your plugin safe? Known flaws in popular WordPress plugins.

Most WordPress hacks get in through a plugin with a known flaw, either because it wasn't updated or because there's no fix yet. Pick a plugin to see every known vulnerability and the version you should be running.

ACF

A plugin for adding custom fields to posts, pages and other content.

See the vulnerabilities

All in One SEO

An SEO plugin for page titles, descriptions, sitemaps and schema.

See the vulnerabilities

All-in-One WP Migration

A plugin for moving a WordPress site to a new host or domain.

See the vulnerabilities

Contact Form 7

One of the oldest and most widely used contact form plugins for WordPress.

See the vulnerabilities

Duplicator

A plugin for migrating, copying and backing up WordPress sites.

See the vulnerabilities

Elementor

A drag-and-drop page builder, and one of the most widely used plugins on WordPress.

See the vulnerabilities

Elementor Pro

The paid version of Elementor, adding theme building, forms, popups and WooCommerce widgets.

See the vulnerabilities

Essential Addons

A collection of extra widgets and extensions for the Elementor page builder.

See the vulnerabilities

Forminator

A free form, quiz and poll builder from WPMU DEV.

See the vulnerabilities

Gravity Forms

A paid form builder that's popular with agencies and businesses.

See the vulnerabilities

Jetpack

Automattic's all-in-one plugin for security, performance, backups and site stats.

See the vulnerabilities

LiteSpeed Cache

A caching and speed plugin, mainly for sites on LiteSpeed web servers.

See the vulnerabilities

Mailchimp for WordPress

A plugin that connects your site's sign-up forms to Mailchimp.

See the vulnerabilities

Ninja Forms

A drag-and-drop form builder with paid add-ons.

See the vulnerabilities

Rank Math

An SEO plugin for page titles, descriptions, sitemaps, schema and redirects.

See the vulnerabilities

Really Simple Security

A plugin that moves a site to HTTPS and adds security settings. It used to be called Really Simple SSL.

See the vulnerabilities

The Events Calendar

A plugin for creating and managing events on a WordPress site.

See the vulnerabilities

UpdraftPlus

A backup plugin that saves copies of your site to cloud storage.

See the vulnerabilities

W3 Total Cache

A long-standing caching and speed plugin.

See the vulnerabilities

WooCommerce

The most popular way to run an online shop on WordPress.

See the vulnerabilities

WP Fastest Cache

A simple caching plugin for speeding up WordPress.

See the vulnerabilities

WP File Manager

A plugin for managing your site's files from inside the WordPress dashboard.

See the vulnerabilities

WPForms Lite

The free version of WPForms, a drag-and-drop form builder.

See the vulnerabilities

Yoast SEO

An SEO plugin for page titles, descriptions, sitemaps and structured data.

See the vulnerabilities

Not sure what you're running?

Check your whole site in one go.

Our free security check looks at your WordPress version, and the plugins and theme it can see from the outside, for known flaws. It emails you a plain-English report. No logins needed.

Vulnerability data comes from Wordfence Intelligence. Each plugin page links to the full records and carries the data's copyright notices and licences.

Not sure yet?

Find out how exposed your site is.

Send us your site address and get a free, plain-English report of what we find. We check from the outside, so there are no logins to hand over and nothing to install.

Security check
yourbusiness.com
Example
1 urgent2 to fix
  • Known vulnerability in 1 pluginGallery plugin, file upload flawUrgent
  • WordPress is out of dateRunning 6.7.1, latest is 6.8.3To fix
  • 6 plugins and 1 theme out of dateOldest is 14 months behindTo fix