
A headline says a plugin used on hundreds of thousands of WordPress sites has a critical flaw, and the first thing you want to know is simple: is it on my site? You may not remember every plugin your site runs, or which versions are installed, or whether a backup exists that you could actually restore. That is a normal place to be, and it is fixable in about ten minutes with screens you already have. A WordPress plugin security update check comes down to a short routine: list every plugin, match each version against its advisory, back up, update the security fix first, test the pages that matter, and watch for signs of trouble. This post walks through that routine in the order you would do it. It also uses one real flaw, in WPvivid Backup & Migration, as a worked example so you can see how an advisory reads next to your own version number. Nothing here needs a developer for the first pass.
Key Takeaways
Plugins > Installed Plugins shows every active and inactive plugin with its version and any update waiting, and that list is the only way to answer "is it on my site."
Compare each installed version with the advisory's affected and patched versions, confirm a restorable backup of files and database, then update the security fix first and test your key pages.
A patch closes the flaw, but unknown administrators, redirects, spam pages or malware warnings need a separate investigation.
Open the Plugins screen and write down every plugin and version
Log in to WordPress admin and open Plugins > Installed Plugins. The WordPress.org plugin documentation describes this screen: it lists active and inactive plugins, the installed version of each, and an "Update now" link beside any plugin with a newer version waiting. Dashboard > Updates lists the same pending plugin updates in one place.
Copy the list into a note or spreadsheet with three columns: plugin name, installed version, update waiting or not. Include the inactive plugins. A plugin you switched off but never deleted still has its files on the server, so it belongs on the list until you remove it through WordPress.
One gap to know about: must-use plugins, the ones stored in the `wp-content/mu-plugins` folder, do not appear on the normal Plugins screen. If a developer or host set up your site, ask whether any exist. Your host's control panel or a file manager can show that folder.

Match each version to its advisory before you call anything urgent
An update notice does not tell you whether the update is a security fix. The advisory does. For any plugin you worry about, look up its name and your installed version in these places, and read the affected versions and the patched version side by side:
- The plugin's own page and changelog on WordPress.org, or the vendor's site for paid plugins.
- Wordfence Intelligence, which publishes plugin advisories.
- The Patchstack vulnerability database.
- WPScan, another plugin vulnerability database.
- The CVE record on the National Vulnerability Database, for the severity score and affected-version details.
Three words get mixed up in headlines, and they mean different things. Vulnerable means a known weakness exists in a version of the software. Exploited means an attacker has used it. Compromised means a particular site shows evidence of unauthorized access or changes. A critical severity score says how serious a flaw could be, and the National Vulnerability Database describes the CVSS score as a measure of severity, not a complete measure of risk. It does not say your site was attacked. When a flaw is being exploited in the wild, the place to look for that fact is CISA's Known Exploited Vulnerabilities Catalog.
WPvivid shows what a matched advisory looks like
The flaw behind the "900,000 sites" headline, read from its original sources, is a good worked example. It is not a new story. Wordfence published its advisory on February 10, 2026, and the plugin has been patched since. It works well as an example because the advisory spells out exactly what to compare.
| Item | What the advisory says |
|---|---|
| Plugin | WPvivid Backup & Migration |
| Advisory | Wordfence, February 10, 2026 |
| CVE | CVE-2026-1357 |
| Severity | CVSS 9.8, Critical |
| Type of flaw | Unauthenticated arbitrary file upload, which can lead to remote code execution |
| Affected versions | 0.9.123 and earlier |
| Patched version | 0.9.124 |
| Installs | More than 800,000 active, per Wordfence |
| Exploitation | Not reported in Wordfence's advisory; check the CISA known exploited list |
Read that against your list. If you do not run WPvivid, this flaw is not on your site. If you do, check the version number: 0.9.124 or later is the patched release, and 0.9.123 or earlier needs updating.
Two details change how worried to be. First, Wordfence says the critical condition applies to sites that have generated the plugin's "receive backup from another site" key. That feature is off by default, and the keys expire after a maximum of 24 hours. Second, the install count describes the plugin, not the number of exposed sites. The figure of "900,000+" in other reporting is not the number in Wordfence's advisory, which says more than 800,000. A plugin installed on hundreds of thousands of sites is not vulnerable on every one of them, so match your version before you act. You can read the original in the Wordfence advisory and the CVE-2026-1357 record.
Use the same steps for the next advisory, whatever the plugin is. If your version is in the affected range, update. If it is already at or past the patched version, you are done with that one. If you cannot tell, treat the plugin as the next thing to check, not a reason to panic.
Confirm a restorable backup before you touch an update
WordPress.org tells you to take a current backup before updating plugins. Make it a backup of two things, your site files and your database, and make sure you know how to restore it. A backup file you have never tried to restore is a hope, not a plan. If your host offers one-click restore points, note where that button is before you need it. If no recent backup exists, create one first, even if the advisory feels urgent. The few minutes it takes are the cheapest insurance in this routine.
Record the version of each plugin before you update it. If something breaks, you will know exactly what changed and what to roll back to.

Update the security fix first, then the rest one at a time
Read the update notes for the plugin that carries the fix, then update it before anything else. If your site has a staging copy, try the update there first. On a live site without staging, pick a quiet hour.
Then update the remaining plugins one at a time, or in a small group, rather than clicking the bulk update for all of them at once. When something breaks after a single update, you know which one did it. After each plugin, take the next step in the next section before moving on.
You can also turn on auto-updates. In WordPress 5.5 and later, the Automatic Updates column on the Installed Plugins screen lets you enable them for one plugin or several with a bulk action. WordPress checks for scheduled updates twice a day and emails you about successful and failed attempts, according to the WordPress.org auto-update documentation. Auto-updates close the delay between a patch and your site, but they rely on WP-Cron and can fail because of server, hosting or plugin conditions. So, keep the backups and the test routine either way. A sensible middle path is to switch auto-updates on for plugins that are low risk to your business pages and update the checkout, booking and form plugins by hand.
Test the pages that earn money after every update
After each update, spend two minutes on what your business depends on. Open the homepage, then your contact form and send a test message. Log in to the admin area. Walk through checkout or booking if you have it. Click through the menus, open a few key pages on your phone and on a computer, and confirm the updated plugin still shows as active.
If something looks wrong, you have two options: restore the backup, or use your host's rollback. Either puts you back where you started with the old version still installed. If the problem was a conflict, you can ask the plugin's support forum or a developer to look at it, and you can wait for a compatible release before trying again.
| Check | What to look for |
|---|---|
| Homepage | Loads with no layout break or error message |
| Contact form | A test message sends and reaches your inbox |
| Login | You can sign in to the admin area |
| Checkout or booking | A test order or booking completes |
| Menus and key pages | Links work on a phone and on a computer |
| Plugin status | The updated plugin is still active |
A normal plugin conflict is not proof of a hack. A form that stops sending or a layout that shifts after an update is usually a compatibility problem, so record what changed and when, then fix or roll back.

Some signs mean the site needs more than an update
Updating closes a disclosed flaw. It does not tell you whether someone used the flaw earlier, and it does not clean up anything left behind. The WordPress.org guidance on a hacked site and Wordfence's help page for hacked sites point to the same set of warning signs:
- Administrator accounts you do not recognize.
- New or changed PHP files you did not add.
- Redirects to other sites, or spam pages and links on yours.
- A browser or search engine malware warning.
- Unexpected email activity from your domain, or a hosting suspension.
- Passwords that stopped working, or a sudden drop in speed.
If you see one of these, change the order. Write down what you saw, when you noticed it and which plugins updated recently. Save a copy of the current files and database if you can, then contact your host, because they can sometimes isolate the site and often have scan logs. Change your WordPress, hosting, FTP, database and email passwords and sign out other sessions. Run a malware scan and check the administrator list, recently modified files, scheduled tasks and old copies of the site or backups left in public folders. Wordfence's guide to cleaning a hacked WordPress site lays out that process, and our post on what to do in the first 24 hours after a site is hacked covers the first day in order.
Deleting or reinstalling the vulnerable plugin is not enough if an attacker may already have left a backdoor. If you have none of these signs, there is no reason to assume the worst. You have a plugin to update and a routine to keep.

You can run this check free, and paid help fits specific cases
Everything above uses what WordPress gives you: the Plugins screen, update notices, a backup and a list. You can run it yourself this afternoon and again each month. Our post on what a WordPress plugin vulnerability warning means covers how to tell whether a warning is real before you start.
Paid help starts to make sense in particular situations: you manage several sites, your site takes orders or bookings, custom code ties into your plugins, an update already failed, you have no backup you trust, or any warning sign from the list above has shown up. Then the work is inventory, tested updates, restore checks and, if needed, cleanup, and you can read what ongoing care typically costs in our post on website maintenance pricing. A simple brochure site with no warning signs may need nothing more than a monthly routine.
Do you know how to check a plugin security update?
Pick an answer to begin.
1. Where do you see every installed plugin and its version in WordPress?
2. A plugin advisory lists affected versions up to 0.9.123 and a patched version of 0.9.124. Your site runs 0.9.124. What does that mean?
3. After a security update, you find an administrator account you do not recognize. What now?
Frequently Asked Questions About wordpress plugin security update
How do I check whether my WordPress plugins need a security update?
Open Plugins > Installed Plugins and note every plugin, its version and any update waiting. Then compare the plugins you worry about with their vendor advisory, Wordfence, Patchstack, WPScan and the CVE record.
Should I back up before updating a plugin?
Yes. WordPress.org says to create a current backup first. Back up both the files and the database, and confirm you know how to restore them.
Which version of WPvivid fixes CVE-2026-1357?
Wordfence lists 0.9.124 as the patched version, and 0.9.123 and earlier as affected.
Does a critical severity score mean my site was hacked?
No. CVSS measures how serious a flaw is. It does not mean any site has been attacked. Warning signs on your own site tell you whether to investigate.
Should I turn on automatic plugin updates?
They can shorten the wait between a patch and your site. WordPress.org says they depend on WP-Cron and can fail, so keep backups and test key pages, and consider updating checkout, booking and form plugins by hand.
Is updating a plugin enough if the site already looks strange?
No. Update it, then save a copy of the site, contact your host, change passwords and scan for malware, because a patch does not remove anything an attacker already added.
Wrapping Up
A plugin security update check is a routine, not an emergency drill. Open Plugins, write down every plugin and version, match each against its advisory, confirm a backup you can restore, update the security fix first, test the pages that bring in business, and keep an eye out for the warning signs. WPvivid is one worked example of a flaw that reads clearly once you hold your own version number beside the advisory: more than 800,000 installs by Wordfence's count, affected through 0.9.123, patched in 0.9.124.
Run the same routine monthly and the next headline becomes a five-minute lookup. You will know what you have installed, what your backup covers, and which pages to open after an update. Vulnerable, exploited and compromised stay separate in your mind, and you only escalate when your own site shows a reason.
If you would rather have someone else keep that list, Web Leveling reviews a WordPress site's plugins, versions and backups in a website security audit, and we can walk through an update with you. Start with the free check above, and call on us when you have many sites, a store or booking flow, a failed update or a warning sign. We work with small and medium businesses across the country and overseas. Tell us what your plugin list shows and we will help you read it.
Terms
Plugin security words in this post
Tap a term to see what it means.
Plugin. An add-on that gives a WordPress site a feature, such as forms, backups or a store.
Advisory. A published notice from a security vendor or plugin author that names a flaw and the versions it affects.
CVE. A public identifier for a known security flaw, such as CVE-2026-1357.
CVSS. A 0 to 10 score for how severe a flaw is, which does not show whether a site was attacked.
Auto-update. A WordPress setting that installs a plugin's new version without you clicking Update.
Staging site. A private copy of your site where you can test an update before it reaches the live site.
Must-use plugin. A plugin stored in the mu-plugins folder that does not appear on the normal Plugins screen.




