See all checks
Docs

Update a vulnerable WordPress plugin safely

Updated September 2026

When the vulnerability scan finds a plugin with a known security issue, the run offers two options for it: update it to the version that fixes the issue, or deactivate it. Either way, Relvato then re-runs every check that passed before the change — and if one of them now fails, it undoes the change on its own. You get the fix without betting the store on it.

Update to the fixed version

Each vulnerable plugin on the run shows its installed version and the version that fixes every issue found for it. Click “Update to <version> and verify”, then confirm. Relvato installs exactly that version from wordpress.org — the lowest one with every fix, which is the smallest change that closes the hole.

The card then follows the verification: how many of the re-run checks have finished. It takes a few minutes.

If a check breaks

If any check that passed before the update now fails, Relvato rolls the plugin back to the version you had and holds the fixed version back, so it isn't reinstalled — Roll back a plugin update explains the hold. The card says which check failed and links to its run, and the notification bell tells you too.

After a rollback the vulnerability is open again, so the card offers the other option: deactivate the plugin until the author ships a fix that works on your site. A version that already broke your site is never offered again.

Deactivate and verify

For a plugin Relvato can't update — a paid plugin, or one with no fixed version yet — the card offers “Deactivate and verify”. Relvato deactivates the plugin, re-runs the same checks, and reactivates it automatically if the site turns out to need it.

Relvato never deactivates WooCommerce, which would close the store, or a plugin that other active plugins depend on.

Checks that couldn't run

A check that was skipped — blocked by a firewall, for example — proves nothing either way, so it neither keeps nor undoes the change; the card reports it as unverified. If the checks haven't finished within an hour, Relvato stops waiting and leaves the change in place. And Relvato verifies one change at a time per site, so a failing check always points at one change.

What Relvato offers for a vulnerable plugin

PluginUpdateDeactivate
From wordpress.org, with a known fixYes — to the lowest version that fixes every issueYes
Paid, or not on wordpress.orgNo — update it from its vendorYes
No fix known yet for some issueNoYes
The fixed version already broke this siteNo — that version is held backYes
WooCommerceNo — its update can't be undone safelyNo — it would close the store

FAQ

Why the lowest fixed version, not the latest?

It's the smallest change that closes every known issue, so less can break. Newer releases still arrive through WordPress's own updates, and Relvato checks each one.

Which checks are re-run?

Every enabled check whose latest run passed. A check that was already failing can't make Relvato undo a good update.

Why isn't WooCommerce updated this way?

Its updates migrate the database, and running older WooCommerce code on a newer database isn't supported, so an automatic undo wouldn't be safe. Take a backup and update it from WordPress.

Which plugin version do I need?

The Relvato plugin 1.10.0 or newer. If yours is older, the card asks you to update it first.

Related reading
Docs

Find vulnerable plugins before attackers do

The vulnerability scan checks every plugin and theme against the Wordfence Intelligence feed.