{"id":19026575,"date":"2026-09-22T18:47:08","date_gmt":"2026-09-22T18:47:08","guid":{"rendered":"https:\/\/wordpress.org\/support\/?post_type=topic&#038;p=19026575"},"modified":"2026-09-22T18:51:13","modified_gmt":"2026-09-22T18:51:13","slug":"scanner-not-catching-vulnerable-site","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/scanner-not-catching-vulnerable-site\/","title":{"rendered":"Scanner not catching vulnerable site"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Last week, I discovered this same hack on a site we host. Quite elaborate! I was quite surprised to see that the WordFence scanner did not catch it. The WF plugin was up-to-date. The only item in the &#8220;problem found&#8221; email from WordFence was a medium risk plugin upgrade that was available. Is there a setting I need to enable so that the scanner can find this type of vulnerability?<\/p>\n","protected":false},"template":"","class_list":["post-19026575","topic","type-topic","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19026575","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":1,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19026575\/revisions"}],"predecessor-version":[{"id":19026581,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/19026575\/revisions\/19026581"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=19026575"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}