# Review WordPress vulnerability findings each week

Assign review ownership and record prioritization, remediation, and unresolved items. Check the named site's prerequisites, task result, backup scope and recovery handoff with xCloud.

Canonical: https://xcloud.host/use-cases/operations/review-wordpress-vulnerability-findings-each-week/
Published: 2026-09-30 · Updated: 2026-09-30 · Technical review: 2026-09-30
Evidence: Source reviewed; no production deployment test claimed
Editorial owner: xCloud editorial

Intent: Assign review ownership and record prioritization, remediation, and unresolved items.
For: site-owner, administrator

## Requirements and responsibilities

- Name the team, server, hostname, owner and affected users for the WordPress site. Record the current version and the actual business flow that must survive the change. Confirm the current dashboard form, plan eligibility, and server capacity before committing a resource change. A one-click catalog listing is discovery, not permission or proof that the connected MCP profile can install it. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/)
- Prepare a non-sensitive test input and an acceptance record. Keep access to the app administrator and an independent observer where possible; omit secrets from AI prompts and client reports. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/)
- For WordPress, verify the file and database backup scope and a safe target for recovery. Native scheduling, destination settings, staging synchronization and restore remain dashboard actions. Agree a maintenance window and owner before any action that interrupts the service or overwrites data. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/)

## Illustrative situation

An agency reviews vulnerability findings every Monday across client WordPress sites. A new advisory must be matched to installed versions and assigned without silently changing production.

## Choose the approach

- Triage affected version and enabled feature before prioritizing a finding. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/)
- A virtual patch, update, disablement or replacement each has different verification and residual risk. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/)

## Dashboard and application procedure

### 1. Define weekly scope

**Where:** Agency team inventory

**Permissions:** Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.

**Inputs:** Client site IDs, reviewer, last review date

**Action:** List the sites in scope and confirm granted team access and current WordPress component inventory.

**Expected result:** A review list with no missing client site.

**Verify:** Cross-check domains against contracts and xCloud teams.

**If it fails:** If a client site is inaccessible, log the coverage gap and request access.

Capability: Confirm requirements and inspect resources
Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

### 2. Read current findings

**Where:** xCloud WordPress → Vulnerability Scan

**Permissions:** Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.

**Inputs:** Scan dates, open and resolved findings

**Action:** For each site, inspect new, changed and unresolved findings since prior review. Record component slug, installed version and advisory.

**Expected result:** A dated findings register.

**Verify:** Compare finding version to WordPress installed version.

**If it fails:** If scan is stale, request an authorized rescan rather than treating absence as safe.

Capability: Confirm requirements and inspect resources
Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

### 3. Assess business exposure

**Where:** Vendor advisory and WordPress plugin settings

**Permissions:** Authorized WordPress/WooCommerce application administrator or delegated role with rights for this task; hosting access alone is insufficient.

**Inputs:** Affected range, feature use, user access

**Action:** Read primary advisory and determine if the vulnerable feature is enabled and internet-facing. Note critical forms, booking or commerce dependencies.

**Expected result:** A priority supported by evidence.

**Verify:** Have the site owner confirm feature usage and severity assumptions.

**If it fails:** If exploit evidence is uncertain, label it and escalate; do not invent compromise.

Capability: Configure and test WordPress in its administrator UI
Sources: [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/)

### 4. Assign remediation path

**Where:** Agency ticket and staging plan

**Permissions:** Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.

**Inputs:** Owner, fixed version, deadline, backup

**Action:** Choose update, mitigation, removal or investigation and give each item an owner and review date. Reserve staging tests for business-critical components.

**Expected result:** A queue of explicit decisions.

**Verify:** Check no open high-priority finding lacks an owner.

**If it fails:** If a fix breaks a critical flow, keep the item open with documented temporary controls.

Capability: Confirm requirements and inspect resources
Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [Manage WordPress updates with Updates Manager](https://xcloud.host/docs/manage-wordpress-updates-with-updates-manager/); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/)

### 5. Verify closure next cycle

**Where:** xCloud scan result and change record

**Permissions:** Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.

**Inputs:** Applied versions, scan time, business test

**Action:** After an approved fix by the change owner, read the latest available scan and installed version; request a separately approved rescan if evidence is stale. Retain unresolved items in next report.

**Expected result:** A defensible closure or explicit carryover.

**Verify:** Match test evidence, component version and scan timestamp.

**If it fails:** If the scanner still flags it, investigate before closing the ticket.

Capability: Confirm requirements and inspect resources
Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/)

## Maintenance

- Review this task after app or template updates and at the cadence agreed with the owner. Record failures as dated observations rather than assuming host health proves service health. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/)
- Watch access changes, backup completion, free storage and external providers. Recheck integrations after credential, DNS, mail or source-data changes. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/)

## Recovery decisions

- If the inventory, finding, report or plan is wrong, preserve its dated source evidence and issue a corrected version to the approved owner. Keep the prior record visible as superseded. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/)
- Recheck the exact site, timestamp and task-specific test before approving any separate change. A bad review does not by itself justify replacing live site data. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/)

## AI handoff

Connect an authorized xCloud MCP profile and discover its exact tools and team scope. The packaged REST wrapper is GET-only; use dashboard or app controls for undocumented writes.

### Supported scope

- **Confirm requirements and inspect resources** (mcp; read): Discover the connected profile and operation schema first; only teams granted to the connection are visible. Checkpoint: Confirm exact team, server and site identity. Use dashboard\_url returned by the resource; do not invent a dashboard link. Operation identifiers to discover: teams.index, servers.show, sites.show. Scopes: read:servers, read:sites. Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

### Copyable agent brief

```text
Read-only: inspect authorized client sites, scan dates, installed versions and findings. Return exact affected slugs, advisory questions and owner gaps. Do not rescan, update, restore or mark findings resolved; app/vendor review and any writes need separate approval.
```

### Manual checkpoints

- Approve exact site, target, cost and any write or maintenance window after inspecting the proposed plan.
- An authorized WordPress administrator must configure and test app users, content, integrations and business rules in the app.
- Native WordPress staging, backup schedule/settings, push/pull and all restores are dashboard-only; Docker restore is dashboard-only and replaces state.
- Reconcile data created after the chosen recovery point before any destructive restore.

## Feature coverage

- **weekly-vulnerabilities decision, evidence and task action** (covered): The procedure identifies the authorized task boundary and observable result. Steps: step-1, step-2, step-3, step-4
- **backup, ongoing operation and recovery** (covered): Recovery and maintenance are checked in the task procedure. Steps: step-4, step-5

## Sources

- [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md) — reviewed 2026-09-30; v4.4.2 package; xCloud v2.8.8 capability review
- [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs) — reviewed 2026-09-30
- [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/) — reviewed 2026-09-30
- [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/) — reviewed 2026-09-30
- [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/) — reviewed 2026-09-30
- [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/) — reviewed 2026-09-30
- [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/) — reviewed 2026-09-30
- [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/) — reviewed 2026-09-30
- [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/) — reviewed 2026-09-30
- [Manage WordPress updates with Updates Manager](https://xcloud.host/docs/manage-wordpress-updates-with-updates-manager/) — reviewed 2026-09-30
- [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/) — reviewed 2026-09-30

## Continue

[Explore all use cases](https://xcloud.host/use-cases/)

- [Manage WordPress plugin updates and security checks](https://xcloud.host/use-cases/operations/wordpress-plugin-updates-and-security/)
- [Release WordPress staging changes without losing live data](https://xcloud.host/use-cases/playbooks/wordpress-staging-release-with-live-data/)
