Cloudflare

Cloudflare

CDN & Securitycloudflare.com

Global CDN and security platform protecting millions of websites.

3.4M
WordPress Sites Tracked on Cloudflare
3.4M
Sites Detected
1.3
Avg Plugins / Site
-0.5 vs avg
343K
Vuln Exposure
sites with outdated plugins
46 / 50
Plugins with CVEs
1 unpatched
WordPress Versions
6.9.1
188K31.7%
6.9.4
118K19.9%
6.8.3
42K7.1%
6.8.5
19K3.2%
6.9.3
17K2.9%
6.9
14K2.4%
6.7.4
12K2.1%
6.8.2
9K1.6%
6.7.5
8K1.4%
6.6.4
7K1.2%
6.0.11
6K1.1%
6.8.1
6K1.0%
6.4.7
5K0.9%
6.5.7
5K0.9%
6.7.2
5K0.8%

Summary

Most Common
6.9.1
Version Coverage
18%
of sites have detectable WP version
Unique Versions
669
Most Popular Plugins
Top 50
1 of the top 50 plugins on Cloudflare have unpatched vulnerabilities.

Vulnerable Version Usage

Sites running outdated (vulnerable) vs safe versions of top plugins

Complianz – GDPR/CCPA Cookie Consent100% vulnerable
Elementor Website Builder – more than just a page builder70.7% vulnerable
Spam protection, Honeypot, Anti-Spam by CleanTalk65.6% vulnerable
Jetpack – WP Security, Backup, Speed, & Growth52.5% vulnerable
TablePress – Tables in WordPress made easy47.9% vulnerable
Contact Form 744.2% vulnerable
Ultimate Addons for Elementor41.1% vulnerable
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic28.4% vulnerable

Plugin Security Overview

Breakdown of 50 most popular plugins on Cloudflare

50plugins
No known CVEs4
CVEs (all patched)45
Unpatched CVEs1
Est. exposed sites
343K
plugins on Cloudflare — sorted by prevalence
#PluginCVEs
1
SlideShow Press
0
2
Contact Form 7
8
Version distribution on Cloudflare (526 versions detected)
6.1.5
111K30.0%
6.1.4
30K8.0%
6.0.6
15K4.0%
5.9.8
13K3.4%vuln
6.1.1
11K3.0%
6.1.3
8K2.2%
5.7.7
7K1.9%vuln
6.1
7K1.8%
6.1.2
6K1.7%
5.5.6
4K1.2%vuln
+516 more versions
3
Meta Generator and Version Info Remover
0
420
547
626
72
84
91
101
1124
12
WP-PageNavi
0
1310
1410
15
EWWW Image Optimizer
6
1613
17
Ultimate Addons for Elementor
12
18
Table of Contents Plus
5
199
205
Most Popular Themes
cocoon-master
#1
98K sites

cocoon-master

No CVEs
cocoon-child-master
#2
64K sites

cocoon-child-master

No CVEs
Hello Elementor
#3
56K sites

Hello Elementor

by elemntor

Hello Elementor is a lightweight and minimalist WordPress theme that was built specifically to work seamlessly with the Elementor site builder plugin. The theme is free, open-source, and designed for users who want a flexible, easy-to-use, and customizable website. The theme, which is optimized for performance, provides a solid foundation for users to build their own unique designs using the Elementor drag-and-drop site builder. Its simplicity and flexibility make it a great choice for both beginners and experienced Web Creators.

1.0M 1 CVE
Astra
#4
35K sites

Astra

by brainstormforce

The Astra WordPress theme is lightning-fast and highly customizable. It has over 1 million downloads and the only theme in the world with 6,000+ five-star reviews! It’s ideal for professional web designers, solopreneurs, small businesses, eCommerce, membership sites and any type of website. It offers special features and templates so it works perfectly with all page builders like Spectra, Elementor, Beaver Builder, etc. Fast performance, clean code, mobile-first design and schema markup are all built-in, making the theme exceptionally SEO-friendly. It’s fully compatible with WooCommerce, SureCart and other eCommerce plugins and comes with lots of store-friendly features and templates. Astra also provides expert support for free users. A dedicated team of fully trained WordPress experts are on hand to help with every aspect of the theme. Try the live demo of Astra: https://zipwp.org/themes/astra/

1.0M 3 CVEs
bb-theme
#5
19K sites

bb-theme

No CVEs
jin
#6
16K sites

jin

No CVEs
flatsome
#7
14K sites

flatsome

4 CVEs
dt-the7
#8
12K sites

dt-the7

8 CVEs
GeneratePress
#9
12K sites

GeneratePress

by edge22

GeneratePress is a lightweight WordPress theme built with a focus on speed and usability. Performance is important to us, which is why a fresh GeneratePress install adds less than 10kb (gzipped) to your page size. We take full advantage of the block editor (Gutenberg), which gives you more control over creating your content. If you use page builders, GeneratePress is the right theme for you. It is completely compatible with all major page builders, including Beaver Builder and Elementor. Thanks to our emphasis on WordPress coding standards, we can boast full compatibility with all well-coded plugins, including WooCommerce. GeneratePress is fully responsive, uses valid HTML/CSS, and is translated into over 25 languages by our amazing community of users. A few of our many features include 60+ color controls, powerful dynamic typography, 5 navigation locations, 5 sidebar layouts, dropdown menus (click or hover), and 9 widget areas. Learn more and check out our powerful premium version at https://generatepress.com

500K No CVEs
bb-theme-child
#10
11K sites

bb-theme-child

No CVEs
factory-templates-4
#11
9K sites

factory-templates-4

No CVEs
jannah
#12
9K sites

jannah

1 unpatched
showit
#13
8K sites

showit

No CVEs
hello-theme-child-master
#14
8K sites

hello-theme-child-master

No CVEs
flatsome-child
#15
8K sites

flatsome-child

No CVEs
Vulnerable Sites

These sites on Cloudflare are running outdated plugin versions with known security vulnerabilities. Domain names are partially masked for privacy.

vulnerable domains on Cloudflare
DomainVulnerable Plugins
j.***.mv
www.**********.com
wfp.***********.jp
www.**********.ar
pul**********.br
www**********.co
www*********.dz
www2***********.jp
gui*********.com
par*********.nz
ude*******.uy
hma*******.com
inte*****************.com
k-*****.com
www********.ng
home**************.at
www*********.com
ann*******.fr
mp.m**********.com
myv*******.za

Showing 20 of the most affected sites. Run a free audit to check if your site is affected.

Is your Cloudflare site secure?

Run a free audit to check your plugins, themes, and WordPress version against our vulnerability database.