All posts
April 2021·5 min read

Why keeping your plugins updated is your most important WordPress security task

WordPress core is well-maintained and promptly patched. Plugins are a different story. Plugin vulnerabilities are now the most common way WordPress sites get compromised — more than weak passwords, more than outdated core.

Where WordPress compromises actually come from

Security research published in recent years has consistently found that vulnerable plugins and themes are the primary attack vector for WordPress compromises. The Wordfence and Sucuri annual reports put this figure at over 50% of compromises — ahead of weak passwords, ahead of outdated WordPress core, ahead of brute-force attacks.

The reasons are structural. WordPress core is maintained by a dedicated security team, has a formal vulnerability disclosure process, and receives rapid patches. Popular plugins range from well-maintained commercial products with security teams of their own to hobbyist projects that may not receive updates for months. A site running 20 plugins has 20 separate maintenance responsibilities, each with its own risk profile.

How plugin vulnerabilities are exploited

When a security researcher finds a vulnerability in a WordPress plugin, they typically report it to the plugin developer under a responsible disclosure process. The developer patches it. The patch is submitted to the WordPress.org plugin repository. WordPress notifies site owners of the available update.

The problem is that interval — the time between the patch being available and site owners actually applying it. In some cases this is days. In many cases it's weeks. In some cases it's never. During that window, if details of the vulnerability become public (which they typically do once patched), attackers scan for sites still running the vulnerable version and exploit them at scale.

The specific plugins with the highest risk

Not all plugins carry equal risk. The highest vulnerability count tends to be in:

  • Contact form plugins — they handle user input and are often complex
  • Page builders (Elementor, Divi, Visual Composer) — large, complex codebases
  • File management and upload plugins — any plugin handling file uploads has elevated risk
  • E-commerce plugins — WooCommerce and its extension ecosystem handle sensitive data
  • Membership and subscription plugins — complex authentication handling

Popularity is a double-edged sword: widely-used plugins are more thoroughly scrutinised by security researchers (good for finding and patching vulnerabilities quickly) but are also the most targeted by attackers (bad when they do have a vulnerability).

WordPress 5.5 auto-updates for plugins

WordPress 5.5 (released August 2020) added optional automatic updates for plugins and themes. You can enable auto-updates per plugin in the Plugins list in wp-admin, or enable them for all plugins at once.

The same considerations apply as for core auto-updates: security benefit vs. compatibility risk. For a site under active development, auto-updating all plugins without testing could cause problems. For a stable business site not under active development, auto-updates for plugins reduce the risk of a vulnerability sitting unpatched for weeks.

The plugin you're not using is still a risk

Deactivated plugins still exist on your server. An attacker who exploits a vulnerability in a deactivated plugin can still compromise your site — the code is still there, even if WordPress isn't loading it. If you're not using a plugin, delete it entirely, not just deactivate it.

Review your installed plugins periodically. Remove anything you don't actively use. Each plugin you delete reduces your attack surface permanently.


At DownUnder WP, plugin and theme updates are managed from your dashboard with a single click per item. You can see available updates, what's installed, and apply them without touching SSH or FTP.

Australian WordPress hosting from $5/month

Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.