This article is also available in:

How vulnerabilities work in Modular DS

When you manage several WordPress sites, sooner or later one of them will end up with a vulnerability in a plugin, a theme or its WordPress version. It's not bad luck, it's the reality of the ecosystem: last year alone, more than 12,000 WordPress vulnerabilities were discovered according to Patchstack.


Modular DS detects those vulnerabilities and shows you in one place which ones affect your sites, how serious they are and what you can do about each one. Here we explain where that information comes from, how to interpret it and what options you have to resolve each case.


Where to see your vulnerabilities


Modular DS shows your vulnerabilities in two places, depending on what you're doing at any given moment.


In the global updater, each affected plugin is flagged so you can spot it at a glance while you review the updates across all your sites.


You can use the vulnerabilities filter to keep only what has a pending security issue. The same happens in each individual site's updater.




In each site's Health & Security section you get the full view. The vulnerabilities tab gathers everything detected on that site, organized by source: plugins, themes, WordPress version, PHP version and database (MariaDB or MySQL).




Where the information comes from


Vulnerabilities in WordPress, plugins and themes come from Patchstack, the leading WordPress security company. Patchstack maintains a database of known vulnerabilities and Modular DS cross-references it with what you have installed on each site.


Vulnerabilities in PHP and the database come from WP Vulnerability, an open database specialized in the components around WordPress. This way, your security information doesn't stop at plugins and themes, but also covers the foundation your site runs on.


In each vulnerability's detail you'll always find a link to the original report, whether it's the Patchstack one or the relevant CVE report.


A CVE (short for Common Vulnerabilities and Exposures) is the public, standard identifier assigned to a specific vulnerability, so that anyone can look it up and know exactly what it involves.


Vulnerability severity


Each vulnerability comes with a severity label that tells you at a glance how serious the problem is.


The higher the severity, the more dangerous the vulnerability and the more priority you should give it. A high vulnerability points to a serious risk worth addressing as soon as possible, while a low one is a minor risk. From a score of 75 upwards it's considered critical, the level you should pay the most attention to.


This severity is assigned by Patchstack based on the nature of each vulnerability or what the CVE report states. That's why the same criteria are applied consistently across all the sites you manage.


Affected versions


If a vulnerability shows up on your site, it's because you have an affected version installed. It's not a preventive alert: the component and version you're using are within the vulnerable range.


The important thing in this section is something else: before updating, check that the version you're moving to isn't also affected. A vulnerability can span several versions, and even several different branches, so updating to the latest one doesn't always take you out of the vulnerable range.


This often happens with PHP. You can move up a version thinking you're resolving the alert and find that the new one is also affected. Reviewing the affected versions in the report makes sure you update to a genuinely safe version.


How to fix a vulnerability


When you open a vulnerability's detail, you'll see whether it has a solution available or not. That gives you two main scenarios.


A solution is available. In practice, this almost always means there's a new version of the plugin or theme that fixes the problem. You just update to a safe version from Modular DS and the vulnerability disappears.


No solution available. This happens when the plugin or theme developer hasn't released a fix yet. In that case you can't resolve it by updating, because there's no safe version to move to.



This is where Patch & Protect comes in, the Modular DS security add-on powered by Patchstack. When Patchstack has released a virtual patch for that vulnerability, Patch & Protect applies it and blocks the attack without modifying your site's code or waiting for the official update.


It's the best way to protect your sites during that window of time when the vulnerability exists but there's still no version that fixes it.


PHP and database vulnerabilities


Not all vulnerabilities come from plugins, themes or WordPress itself. They can also appear in the PHP version or in the database (MariaDB or MySQL), and these are handled differently.


For PHP ones, the solution is to update the PHP version to one that isn't affected. That change is made from your hosting panel, not from Modular DS. Remember to review the affected versions so you don't switch to another one that still has the problem.


For database ones, there's nothing you can update yourself from Modular DS or from WordPress. The only possible action is to confirm with your hosting provider that they're already applying a patch or some security measure against those vulnerabilities.


Keep one thing in mind that confuses many users: if you ask your hosting to update the database and they say no, it's usually not a bad sign. In most cases it means they already have those vulnerabilities under control through other means, and that's why they don't need to touch the version.


The red PHP box isn't a vulnerability


This distinction causes confusion, so let's make it clear. In the site status view, the PHP version can appear in a red box. That color doesn't mean you have a vulnerability: it only warns you that you're using a PHP version that no longer receives official support.



They're two independent things. You can resolve every PHP vulnerability and still see the box in red if your version is still old. And the other way around: a supported version can have specific vulnerabilities.


If you've fixed the vulnerability but the box stays red, what it's asking you to do is update to a more recent, supported PHP version.


Get notified when a vulnerability appears


You don't need to go in and check every site every day. From your notification settings you can enable vulnerability alerts and find out the moment a new one is detected on any of your sites, without having to keep an eye on the dashboard.



You can adjust which channels you want to receive these alerts through in your account's notification settings.


Stay ahead of vulnerabilities


Beyond the alerts, you can have Modular DS act for you. When you create a plugin update automation, you can set it to update immediately as soon as a vulnerability is detected. That way, if the developer releases a version that fixes the flaw, Modular DS applies it without you having to step in.


And for the cases where there's still no update, enabling Patch & Protect on your most critical sites gives you a layer of protection until the official fix arrives.





Do you need help with anything else? Email us at help@modulards.com or contact us via the support chat, and we'll be happy to help you.

Updated on: 03/09/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!