MultiCmsManager

Known vulnerabilities

Vulnerability checks for plugins, themes and extensions

Most hacked sites had a plugin with a vulnerability that was already known and already fixed. You just need to know in time.

The problem

The patch exists. The site doesn’t have it.

Every week brings dozens of vulnerabilities in WordPress plugins and Joomla extensions. For an agency with many sites, matching them by hand with what’s installed is impossible.

And not all of them are equally urgent: a serious flaw in an active plugin isn’t the same as a minor one in a disabled plugin.

How it works

Site inventory against the vulnerability database.

  1. 1

    Inventory

    The agent reports core, plugins, themes and extensions installed, with their versions.

  2. 2

    Matching

    We match the inventory against Wordfence Intelligence for WordPress and the Joomla Security Centre for Joomla core.

  3. 3

    Priorities

    Each vulnerability comes with severity, CVE and the version that fixes it. Less urgent ones can be ignored without losing track of them.

In detail

Useful information, not just alarms.

  • Severity and CVSS score for every vulnerability
  • The version that fixes it, or a clear note that no fix exists yet
  • Active and disabled plugins told apart: a disabled plugin can still be exploited
  • Core versions past end of life, with the upgrade path
  • Vulnerabilities can be ignored in one click and still reviewed separately
  • Safe update with rollback straight from the site page

FAQ

Frequently asked questions

Where does the vulnerability data come from?

From Wordfence Intelligence for WordPress core, plugins and themes, and from the Joomla Security Centre for Joomla core.

How often is the check run?

At every site sync and whenever the vulnerability database is updated.

Can I hide a low-severity vulnerability?

Yes, you can ignore it: it leaves the counts and alerts but stays visible in a separate list, and you can restore it any time.

Try it on your clients’ sites.

During the beta we welcome agencies in small groups and set up the first sites together.