launch week Respira for WordPress is live on DevHunt until Monday. Live on DevHunt this week. See the launch

Attackers reach WordPress sites within hours of a fix. Check yours in 20 seconds.

A core flaw exploited within hours of its patch, a WooCommerce plugin attacked seven months after its fix. How attackers pick WordPress sites, how to check yours for free without installing anything, and what to do with what you find.

A WordPress security release used to buy a few days. In September it bought a few hours.

I built a free scanner for this, and the reason is in the dates below. Nothing in this article needs a plugin, a login or an account to try.

Two clocks

On 22 September WordPress fixed CVE-2026-87902, a flaw in core that lets someone with no login make WordPress load a PHP file from outside the active theme (record). A working exploit was published the same day, and SecurityWeek reported that Patchstack saw it used against sites within hours. CISA added it to its Known Exploited Vulnerabilities catalog three days later. The fixed releases are 7.1.2, 7.0.6 and 6.9.9, with backports down to 4.7.37, and the September roundup has the rest of that month.

That is the fast clock. The slow one is worse, because nobody is watching it. WooCommerce Wholesale Lead Capture had a critical flaw, rated 9.8, fixed in version 2.0.3.2 on 20 February (record). In September, seven months later, Wordfence reported blocking more than 100,000 attacks on it. In June, Everest Forms Pro drew more than 29,300 attempts on a flaw of the same rating, fixed in 1.9.13 (record, report).

Every one of those attacks went to a site where the fix already existed and had not been installed. Nobody has to be first to a new bug. Old bugs on sites nobody updates are enough.

How sites get picked

Most WordPress sites tell anyone who asks what they run. Three places give it away:

  • The generator tag in the page source, and the RSS feed, which name the WordPress version.
  • Stylesheet and script addresses ending in ?ver=, which often carry a plugin's version.
  • Each plugin's readme.txt, public by default, with the version on its "Stable tag" line.

Reading those takes a few ordinary requests and no skill. Hiding them helps less than it sounds, because an attacker can try the exploit and skip the check. Updating is what closes the door. Reading them yourself first tells you which doors are open.

Check your WordPress site in 20 seconds

The free WordPress vulnerability scanner reads those same public signals, from outside, the way a browser does. It never logs in, never submits a form and never sends an attack payload.

  1. Open the scanner and type the site's address.
  2. It reads that page, the feed when the page hides the version, up to 40 plugin readme files and up to 6 theme stylesheets, and stops after 20 seconds.
  3. Every version it can read is matched against more than 41,000 records from the Wordfence Intelligence database, refreshed every six hours.
A public scan of shop.example.com: WordPress 6.4.2 read from its generator tag, 5 plugins and 1 theme found, 96 known vulnerabilities in 6 components, with Really Simple Security rated critical and Elementor and WordPress rated high
The free result for a demo address, shop.example.com, set up with old versions on purpose. It names each affected component, how many known vulnerabilities match and the worst severity.

The free result answers the first question: is anything known to be wrong with the versions this site shows. A free respira.press account answers the next one. It lists every record with its CVE and the version that fixes it, writes a fix prompt, and re-checks up to 25 sites every week, so a record published next month reaches the site you scanned today.

The free scan, the free account and the full Respira scan in 40 seconds, with a voice. Turn the sound on in the player.

What to do with a finding

A list of CVEs is where most people stop, so the free account turns it into a prompt. Paste it into ChatGPT or Claude, or send it to whoever looks after the site. It asks the assistant to walk you through wp-admin one step at a time and to wait for you between steps.

The fix prompt for shop.example.com with a Copy prompt button. It lists Really Simple Security 9.0.0 to update to 9.8.3, Elementor 3.6.2 to update to 4.1.4 and WordPress core 6.4.2 to update to 6.6.8, each with its Wordfence record link
The fix prompt orders the work by severity and links each item to its Wordfence record.

The prompt follows the order I would use by hand:

  1. Confirm a backup of files and database exists, from your host or a backup plugin, and that you can restore it.
  2. Update the most severe item first, one at a time, to the version named or later.
  3. If WordPress offers a lower version, or no update at all, stop. That is usually a premium plugin with a lapsed licence, and the vendor is the next call.
  4. If no fix is published, deactivate the plugin until one is, or replace it.
  5. After each update, load the home page and one page that matters, checkout or the contact form.
  6. Scan again.

An update closes the hole. It does not undo what came through before. After a critical finding, also look for administrators and application passwords you do not recognise, plugins installed recently that nobody remembers adding, and PHP files under wp-content/uploads.

What an outside check cannot see

A scan from outside sees what the site shows in public. A plugin that loads nothing on the page scanned, or hides its version, is listed as "found, version unknown, not checked" rather than guessed at. A clean result means nothing known matched the versions that were readable. It is not a malware scan.

Two ways to see the rest, one of them free:

  • From inside, free. Inhale and Respira ARC, the two free Respira plugins on WordPress.org, can connect to a free account. The site then reports every plugin and theme with its exact version once a week, including the ones the public pages never mention.
  • The full scan. Respira for WordPress (what each scan checks) also checks core files against the official release, administrator accounts, hidden plugins and whether PHP runs in uploads. Your AI can make the updates from Claude or ChatGPT, with a snapshot before each one. It is paid, after a 7-day free trial.

If you look after a friend's site, a client's, or the one your local club runs, the scanner takes their address as easily as yours. That might be the most useful 20 seconds of their week.

Questions

How fast are WordPress vulnerabilities exploited after a fix?

Sometimes within hours. WordPress fixed the core flaw CVE-2026-87902 on 22 September 2026, a working exploit was published the same day, and SecurityWeek reported attacks within hours. CISA added it to its Known Exploited Vulnerabilities catalog on 25 September. Plugin flaws can be attacked months later too: Wordfence reported blocking more than 100,000 attacks in September 2026 on a WooCommerce plugin fixed in February.

How do I check if my WordPress site is vulnerable without installing a plugin?

Enter the address in the free Respira WordPress vulnerability scanner. It reads the public pages the way a browser does, finds the WordPress, plugin and theme versions they show, and matches them against more than 41,000 records from the Wordfence Intelligence database. It needs no plugin and no login and stops after 20 seconds.

What does a free respira.press account add to the scan?

Every matching record with its CVE and the version that fixes it, a fix prompt to paste into ChatGPT or Claude or send to a developer, and a weekly re-check of up to 25 sites against the database as it grows.

Is a clean result proof that my WordPress site is safe?

No. A clean result means nothing known matched the versions the site shows in public. Plugins that do not show a version are listed as not checked, and a version check cannot tell whether someone got in before you updated. A check from inside the site sees every plugin, and Respira for WordPress also checks core files, administrator accounts and hidden plugins.

What should I do first if the scan finds a vulnerability?

Make sure a backup you can restore exists, then update the most severe item to the version the result names, one item at a time. If no update is offered, often a premium plugin with a lapsed licence, ask the vendor. If no fix is published, deactivate the plugin until one is. Then run the scan again.

Checked on 9 October 2026.

Join the conversation

0 comments · Respira account

No comments yet. Be the first to weigh in.