Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 2.9.1
Security Advisory

WordPress 2.9.1: 47 CVEs Found - Critical Security Update

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
3 websites still running wordpress 2.9.1  → View full list
47
Total
1
Critical
13
High
33
Medium

WordPress 2.9.1 contains 47 known security vulnerabilities that put your website at serious risk. Among these are 1 critical vulnerability and 13 high-severity flaws that could allow attackers to upload malicious files, execute code remotely, and steal sensitive data. If your website is still running this outdated version, immediate action is required to protect your business and your users.

This comprehensive guide will walk you through identifying whether your site is vulnerable, understanding the specific threats you face, and implementing the necessary security updates. With only 3 websites worldwide still using this version, you're likely behind on critical security patches that have been released over the years.

Our security experts have analyzed all 47 CVEs to bring you actionable steps that will take your site from vulnerable to secure in minutes.

What is Wordpress 2.9.1?

WordPress 2.9.1 is an extremely outdated version of the world's most popular content management system, originally released in 2010. At that time, it was considered modern and feature-rich, but over a decade of security research has uncovered numerous vulnerabilities in this and all older WordPress versions. If you're still running WordPress 2.9.1, your site is operating with security standards from an era before modern cybersecurity threats existed.

Think of WordPress 2.9.1 like driving a car from 2010 without any of the safety features, security systems, and crash protection added in newer models. While the basic transportation works, you're missing critical protections that modern vehicles (and modern WordPress versions) now include as standard. Your website faces constant threats from automated bots scanning the internet for vulnerable sites, and WordPress 2.9.1 is like having a giant neon sign advertising that you're an easy target.

Key Vulnerabilities in Wordpress 2.9.1

47 CVEs found. The most critical are explained below.

CRITICAL CVE-2021-24212 9.8/10 · CVSS v3.1 ⏱ Immediate
WooCommerce Help Scout plugin allows anyone to upload files

This vulnerability in the WooCommerce Help Scout plugin lets anyone upload files to your website without logging in first. Files end up in a specific folder that could be accessed or executed by attackers.

Impact: Attackers could upload malicious files that compromise your entire website, steal customer data, or take control of your site completely.

↗ View on NVD
HIGH CVE-2023-0631 8.8/10 · CVSS v3.1 ⏱ Immediate
Paid Memberships Pro plugin database attack vulnerability

The Paid Memberships Pro plugin has a flaw that allows basic members to manipulate database queries through shortcodes. This happens because the plugin doesn't properly filter what members can input.

Impact: Attackers with member accounts could access, steal, or delete sensitive information from your database including customer records and payment data.

↗ View on NVD
HIGH CVE-2024-1962 8.8/10 · CVSS v3.1 ⏱ Within 7 days
CM Download Manager plugin missing security checks

The CM Download Manager plugin is missing security verification checks called CSRF protection. This allows attackers to trick logged-in administrators into making unwanted changes.

Impact: Hackers could trick your admin into modifying or deleting downloads, or making other administrative changes without your knowledge or permission.

↗ View on NVD
HIGH CVE-2023-6967 8.8/10 · CVSS v3.1 ⏱ Immediate
Pods plugin database injection through shortcodes

The Pods plugin doesn't properly clean user input in shortcodes, allowing attackers to inject malicious database commands. This affects many versions of the plugin.

Impact: Attackers could access, modify, or delete your entire database including all customer information, products, and business-critical data.

↗ View on NVD
HIGH CVE-2023-6999 8.8/10 · CVSS v3.1 ⏱ Immediate
Pods plugin allows code execution attacks

The Pods plugin has a critical flaw that lets contributors and other authenticated users execute malicious code on your server through shortcodes.

Impact: Anyone with contributor access or higher could completely take over your website, steal all data, or use it to attack your customers.

↗ View on NVD
HIGH CVE-2022-2798 8.0/10 · CVSS v3.1 ⏱ Within 30 days
Affiliates Manager plugin data injection vulnerability

The Affiliates Manager plugin doesn't properly validate affiliate registration data, allowing attackers to inject malicious code into exported spreadsheets.

Impact: When you export affiliate data to CSV, malicious code in the spreadsheet could compromise your computer or spread to other systems that open the file.

↗ View on NVD

Additional Vulnerabilities (41 more)

Showing first 10 of 41. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2026-27938 HIGH 7.7 2026-02-26 WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.9.1, the `wp-graphql/wp-graphql` repository contains a GitHub Actions workflow (`release.yml`) vulnerable …
CVE-2024-10567 HIGH 7.5 2024-12-04 The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in all versions up t…
CVE-2025-0308 HIGH 7.5 2025-01-18 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection v…
CVE-2024-13681 HIGH 7.5 2025-02-18 The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_admin_get_oembed' function in all versions up to, and inclu…
CVE-2025-1648 HIGH 7.5 2025-02-25 The Yawave plugin for WordPress is vulnerable to SQL Injection via the 'lbid' parameter in all versions up to, and including, 2.9.1 due to insufficient escaping on the user suppli…
CVE-2026-9290 HIGH 7.5 2026-06-06 The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17 via the (profile te…
CVE-2024-13377 HIGH 7.2 2025-01-17 The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alt’ parameter in all versions up to, and including, 2.9.1.3 due to insufficient input…
CVE-2025-4102 HIGH 7.2 2025-06-20 The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_enabled_icons' function i…
CVE-2025-13320 MEDIUM 6.8 2025-12-12 The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supp…
CVE-2024-13691 MEDIUM 6.5 2025-02-18 The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_recordMedia' function in all versions up to, and including,…
Full Report Available

All 47 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 2.9.1?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

Running WordPress 2.9.1 in 2024 is like leaving your front door unlocked with a welcome sign for hackers. The 47 known vulnerabilities - especially the critical file upload flaw and remote code execution issues - create multiple pathways for attackers to compromise your website, steal customer data, or use your site to spread malware. There is no legitimate reason to remain on this version when upgrading is free, automated, and takes just minutes.

Stop gambling with your website security and take action today. SiteRecipe.com's comprehensive security scanning tool instantly identifies all vulnerabilities in your WordPress installation, prioritizes them by severity, and provides step-by-step remediation guidance. Sign up for a free security scan now to see exactly what threats your site faces - it only takes 60 seconds to get a complete vulnerability report and personalized upgrade recommendations.

Frequently Asked Questions

Is WordPress 2.9.1 still supported by Automattic or the WordPress security team?
No. WordPress 2.9.1 has been unsupported since 2010 and receives no security patches, bug fixes, or updates whatsoever. Any vulnerabilities discovered (like the 47 identified here) will never be patched on this version. You must upgrade to a current version to receive ongoing security support.
Will upgrading from WordPress 2.9.1 break my website or delete my content?
Modern WordPress upgrades are designed to be safe and preserve all your content, posts, pages, and user data. However, very old plugins and custom code written for 2.9.1 might not be compatible with current WordPress versions. This is exactly why backing up before upgrading is essential - it gives you a restore point if any incompatibilities arise.
Can I patch individual vulnerabilities instead of upgrading WordPress?
No. There are no patches available for WordPress 2.9.1 vulnerabilities because this version reached end-of-life over a decade ago. The only solution is to upgrade to a currently supported WordPress version (6.x). The upgrade process is straightforward and typically takes 5-10 minutes.
What happens if my site gets hacked due to these vulnerabilities?
Hackers can upload malicious files, execute remote code to take over your site, steal customer data and login credentials, inject spam or malware, and use your site for phishing attacks. Recovery from a hacked site costs thousands and can take weeks. Prevention through updating is far cheaper and easier than recovery.
How do I know which of the 47 CVEs actually affect my site?
All 47 vulnerabilities affect WordPress 2.9.1. However, some also affect specific plugins (like WooCommerce Help Scout or Paid Memberships Pro). SiteRecipe.com's vulnerability scanner checks your exact WordPress version, plugins, and themes to tell you precisely which threats apply to your site.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com