WordPress Core Protection
WordPress itself — the core software your whole site runs on — occasionally has a security issue discovered in it. When that happens, the safe move is always to update WordPress to the fixed version. The hard part is knowing in time: a core issue can be published one day and actively abused within days, and most store owners simply don't hear about it until it's too late.
Flavor closes that awareness gap. It checks your site's WordPress core version against published vulnerability intelligence on a regular schedule, and if your version is affected by a known issue, it tells you right in your WordPress admin — with the fixed version and a direct link to the official record. On the Business plan, for the subset of issues where the risky path can be fenced off, Flavor also offers a one-click mitigation that helps reduce your exposure until you update — a mitigation, never a guarantee.
What this does — and what it honestly can't
This is the important part, so we'll be plain about it.
What Flavor can do:
- Always warn you. On every plan, Flavor detects when your WordPress core version is affected by a known, published vulnerability and shows you a clear warning.
- Sometimes narrow the exploit path. Many attacks reach WordPress through an optional entry point (a specific API endpoint, for example). Where an issue works that way, Flavor can close that entry point for you, reducing that avenue of attack while you get ready to update. It lowers the risk on that path — it does not make your site invulnerable.
What Flavor cannot do:
- It cannot patch WordPress core. No plugin or theme can — only a WordPress core update fixes the underlying flaw. Flavor's mitigation reduces your exposure; it is not a substitute for updating.
- It cannot gate every issue. Some core vulnerabilities have no optional entry point to close. For those, the honest and only contribution is the warning itself, so you can update quickly.
- It cannot guarantee your site won't be compromised. A mitigation is a best-effort measure that lowers your risk during the window before you update — it is not a security guarantee. No plugin, theme, or tool can promise that a site running a known-vulnerable WordPress core is safe. The one thing that truly removes the risk is updating core.
Updating WordPress core is always the real fix. Flavor's protection is a best-effort measure that buys you time and reduces risk in the window before you update — it does not guarantee your site can't be compromised, and it never replaces updating. If you see a warning, update WordPress core as soon as you can.
What you'll see
1. The admin warning
When your WordPress core version is affected by a known issue, administrators see a warning at the top of the WordPress admin. It tells you:
- How serious it is — colour-graded, from informational up to a red critical warning. If the issue is being actively exploited in the wild, it's flagged as critical.
- Which issue(s) — each one links to its official public record and shows its reference ID (its CVE number).
- What to do — the WordPress version that fixes it, and where to update (Dashboard → Updates).
This warning is not dismissible — an active core vulnerability is too important to hide. You don't need to clear it manually: it disappears on its own the next time Flavor checks and finds your updated core version is no longer affected.
This early warning is part of what your active Flavor license provides — Flavor performs the version check as part of its regular licensing check-in. Keep your license active to keep receiving it.
2. The Security screen
For the full picture, go to Appearance → Flavor Options → Security. At the top you'll find the WordPress Core Protection section, which shows one of:
- A green all-clear — "No known vulnerabilities affect your WordPress core version." Flavor is watching, and you're in the clear.
- A "still checking" note — shown briefly on a new install, before the first check has completed.
- A red notice plus a list of the affected issues — each with its name, reference ID, an "exploited in the wild" flag where it applies, and (on Business) its one-click mitigation.
You'll also see when the intelligence was last refreshed. If it hasn't refreshed recently, Flavor says so plainly and asks you to treat the status as advisory — because a very newly-disclosed issue might not be reflected yet. Flavor would rather tell you it's unsure than imply an all-clear it can't guarantee.
The one-click mitigation (Business)
For issues where the exploit path can be fenced off, the Security screen shows an Apply mitigation button next to that issue. Think of it as a temporary risk-reduction measure for the window before you update — a best effort to make the known path harder to reach. It is not a guarantee that your site is safe, and it does not replace updating WordPress core.
How it works:
- You choose to apply it. Nothing is ever changed automatically without your say-so. You click Apply mitigation and confirm.
- Flavor tells you the trade-off first. The confirmation spells out what the mitigation does and what it may affect — for example, blocking an API endpoint will also block any legitimate tool or integration that genuinely uses that endpoint. You decide with your eyes open.
- It reduces your exposure right away — for instance, by blocking the specific endpoint the attack travels through.
- It reverts itself automatically once you update WordPress core to a fixed version. You never have to remember to undo it. You can also Revert it yourself at any time from the same screen.
While a mitigation is active, any related manual setting (such as the "block this endpoint" option in the same Security tab) shows as managed automatically — Flavor takes care of it and releases it when the mitigation reverts, so you never have two controls fighting over the same thing.
Closing an entry point protects you, but if something on your site legitimately uses that entry point — an app, an integration, a custom workflow — it may stop working while the mitigation is active. That's why Flavor asks you to confirm and shows the possible impact first. If a mitigation gets in your way, updating WordPress core (which reverts it automatically) is the cleanest resolution.
If an issue has no one-click mitigation available, the screen says so directly and points you to the only fix that works: updating WordPress core.
What's included on each plan
| Starter | Business | |
|---|---|---|
| Early warning when your core version is affected | ✓ | ✓ |
| "Actively exploited" severity flag | ✓ | ✓ |
| Fixed-version guidance + official links | ✓ | ✓ |
| One-click mitigation to reduce exposure | — | ✓ |
On every plan, updating WordPress core resolves the issue. The Business plan adds the one-click mitigation for the window before you update. If you're on Starter and see a mitigable issue, the Security screen notes that one-click mitigation is a Business feature — and reminds you that updating core resolves it on any plan.
How often it checks
Flavor checks your core version on its regular schedule (roughly twice a day) rather than the instant an issue is published, so a brand-new disclosure typically surfaces within a few hours. Because the check runs quietly in the background, it never slows down your admin.
Where this data comes from
Flavor doesn't guess. The vulnerability information comes from established, public security sources:
- Vulnerability data by Wordfence Intelligence (Defiant, Inc.).
- CVE records are used under the terms of MITRE Corporation, which maintains the CVE program. The "actively exploited" flag is sourced from the CISA Known Exploited Vulnerabilities catalog.
The exact attribution and licence text for each issue is shown alongside the warning itself, and links back to the original published record so you can read the source directly.
In short: Flavor gives you an early-warning system for WordPress core security on every plan, and — on Business — an optional one-click way to reduce your exposure while you get ready to update. It's a genuine head start and a way to lower risk in the meantime — not a guarantee against a breach. The finish line is always the same: update WordPress core.