Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To check whether your WordPress site is running vulnerable software, find its installed WordPress version, check whether that release is supported, and compare it with the affected and fixed versions in the relevant security advisory. Then check plugins and themes too: a current WordPress core version does not establish that every component is safe.

These steps identify outdated or potentially affected software; a version number alone cannot prove that a particular vulnerability applies to your site.

1. Find your WordPress core version

  1. Sign in to your WordPress admin dashboard.
  2. Go to Tools > Site Health > Info.
  3. Expand the WordPress section and note the value beside Version.

This screen reports site information; it does not install updates. To check for available core updates, go to Dashboard > Updates. WordPress.org’s Site Health documentation describes the information available there.

2. Check whether that version is supported

Compare the version you recorded with WordPress.org’s Supported Versions guidance and current release announcements. WordPress.org says the latest major release is the only version currently officially supported. Older branches may receive security backports, but there is no guaranteed schedule or fixed long-term-support period.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
AMBIR ID Card Scanner with Software -PS667 - Automatic Data Extraction for Age Verification, No Subscription One Time Purchase
  • Complete Turnkey Solution – Hardware and software included in a single purchase with no subscription fees or ongoing costs. Everything your small business needs to start scanning IDs professionally right out of the box.
  • Verification Mode – Keeps No Customer Data – Includes a Verification only mode where you can get an instant APPROVED / UNDER AGE / EXPIRED verdict, then the ID data is discarded—nothing saved. A verification log (date, time, register, clerk, result) is your record that a check was performed. Export verification report via CSV file. Ideal for beer, wine, tobacco, and lottery sales.
  • Local Data Storage – All scanned information is stored locally on your system, giving you maximum privacy, security, and control without requiring cloud storage or internet connectivity.
  • USB-Powered Simplicity – Plug the scanner into your PC and you're ready to go. No external power supply needed, no complicated setup. Windows and Mac compatible.
  • Built-In Age Verification – Set customizable age restrictions to automatically flag minors and prevent them from purchasing age-restricted items. Includes expired ID detection to catch invalid credentials.

Release information changes over time. As of October 6, 2026, WordPress.org announced WordPress 7.1.3 as a maintenance and security release with seven security fixes and four bug fixes, and recommended that sites update. This is a dated example, not a permanent “latest version” reference; check the release page for the current status. WordPress 7.1.3 release announcement

3. Verify a specific vulnerability against its advisory

An unsupported or old version deserves attention, but age alone does not show that a named flaw affects your site. First identify the vulnerability or security release, then compare your installed version with the advisory’s affected and fixed ranges.

  • Check whether the advisory lists your exact version or branch as affected.
  • Note the fixed version for that branch, if one is listed.
  • Check any stated prerequisites, such as a particular configuration or component.
  • Confirm whether an update path is available and compatible with your site.

WordPress security release announcements describe the issues fixed and recommend timely updates. For example, WordPress 7.0.4 was announced on August 12, 2026, with a security fix; WordPress 7.1.1, announced September 17, 2026, included 11 security fixes. Those release facts apply to the versions and issues described in their announcements, not automatically to every older installation. WordPress 7.0.4 announcement · WordPress 7.1.1 announcement

Use the WordPress.org security release index as a starting point for core advisories. For a plugin or theme, consult its current official security notice or an authoritative vulnerability record. The affected-version range depends on the particular issue and component.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Check plugins and themes

WordPress core is only one part of a site’s software. Review update notices in Dashboard > Updates, and inspect the Plugins and Themes screens for available updates. Site Health’s Info screen can also help inventory installed plugins and themes. Dashboard Updates documentation · Plugins documentation · Site Health documentation

If you are checking a particular plugin or theme vulnerability, match the installed component version to that issue’s advisory. A WordPress core version check cannot establish the status of every installed component.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

5. Update outdated software carefully

Use Dashboard > Updates to apply available WordPress updates, or use the official WordPress download path. WordPress.org says supported sites may receive automatic background updates. Follow the update guidance for each plugin or theme, and keep a current site backup before manually updating plugins because update problems can occur. WordPress update documentation · Plugin management documentation

After updating, check the installed version again and confirm it meets the fix listed in the relevant advisory. If an update is unavailable or incompatible, contact your host or the software’s maintainer for a supported remediation path rather than assuming that an older release is safe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Optional: use monitoring for ongoing alerts

A scanner can help surface outdated or vulnerable components between manual checks. Wordfence’s 2024 Annual WordPress Security Report describes its scanner alerting site owners to unpatched vulnerable plugins. That is a vendor-described monitoring option, not proof that a particular alert applies to your installation; verify a finding against the relevant component advisory. The report also says that 96% of the vulnerable software types it analyzed were WordPress plugins. That figure describes the report’s analysis, not the likelihood that any individual site is vulnerable. Wordfence 2024 Annual WordPress Security Report

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.