Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 3.0.1
Security Advisory

WordPress 3.0.1: 77 CVEs Found – Critical Security Guide

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
13 websites still running wordpress 3.0.1  → View full list
77
Total
5
Critical
20
High
51
Medium
1
Low

WordPress 3.0.1 is an outdated version that poses significant security risks to your website. Our security analysis has identified 77 known vulnerabilities affecting this version, including 5 critical-severity flaws that could allow attackers to inject malicious code, steal data, or take complete control of your site. If you're still running WordPress 3.0.1, immediate action is required to protect your business and customer data.

This guide will help you identify if your site is vulnerable, understand the specific threats, and implement the necessary security fixes. We've analyzed real-world CVEs affecting WordPress 3.0.1 to provide you with actionable steps to secure your installation before attackers exploit these known weaknesses.

What is Wordpress 3.0.1?

WordPress 3.0.1 is an extremely outdated version of WordPress released over a decade ago. WordPress is a content management system that powers over 40% of all websites on the internet, making it a frequent target for hackers. Version 3.0.1 was released in 2010 and has not received security updates since then, leaving it vulnerable to modern attack techniques. Running this version today is like leaving your front door unlocked—hackers know exactly where to find the weaknesses.

Vulnerabilities in WordPress 3.0.1 don't just affect the core software; they also extend to popular plugins like Pie Register, Kaswara Modern VC Addons, and BeyondCart Connector. These weaknesses allow attackers to inject malicious code, execute unauthorized database commands, upload dangerous files, and escalate their privileges to administrator level. Our research shows 13 websites are still running this vulnerable version, putting them at extreme risk of data breaches and ransomware attacks.

Key Vulnerabilities in Wordpress 3.0.1

77 CVEs found. The most critical are explained below.

CRITICAL CVE-2026-22390 9.9/10 · CVSS v3.1 ⏱ Immediate
Builderall Builder - Attacker Can Inject Malicious Code

The Builderall Builder plugin has a vulnerability that allows hackers to inject their own code into your website. This code runs on your server with full control, letting attackers do whatever they want with your site.

Impact: Attackers could steal customer data, install malware, redirect visitors to scam sites, or completely take over your website's functionality.

↗ View on NVD
CRITICAL CVE-2018-10969 9.8/10 · CVSS v3.0 ⏱ Immediate
Pie Register - Database Attack Through Invitation Codes

The Pie Register plugin has a flaw in how it handles invitation codes that lets hackers directly access and manipulate your database. They can read, modify, or delete sensitive information stored in your WordPress database.

Impact: Attackers could steal all your customer information, membership data, or any other sensitive data stored in your database without needing a password.

↗ View on NVD
CRITICAL CVE-2021-24284 9.8/10 · CVSS v3.1 ⏱ Immediate
Kaswara VC Addons - Unauthorized File Upload Vulnerability

The Kaswara Modern VC Addons plugin allows anyone to upload files to your website without permission or login. Attackers can upload harmful files like malicious code disguised as fonts.

Impact: Hackers can upload malware, backdoors, or malicious scripts that give them persistent access to your website and full control over it.

↗ View on NVD
CRITICAL CVE-2025-8570 9.8/10 · CVSS v3.1 ⏱ Immediate
BeyondCart - Attackers Can Gain Admin Privileges

The BeyondCart Connector plugin has weak security in how it manages access tokens, allowing attackers to forge valid credentials without needing a real login account. This gives them the same permissions as an administrator.

Impact: Attackers can gain complete control of your website, access all data, modify content, add new admin accounts, and perform any action an administrator could do.

↗ View on NVD
CRITICAL CVE-2024-5021 9.3/10 · CVSS v3.1 ⏱ Immediate
Media Gallery - Server Request Forgery Vulnerability

The Picture/Portfolio/Media Gallery plugin has a flaw that lets attackers use your website server to make requests to other websites or internal systems. Your server becomes a tool for attacking other targets.

Impact: Attackers can access internal company systems, retrieve sensitive information, attack other websites using your server, or access files that should be private.

↗ View on NVD
HIGH CVE-2014-7297 10.0/10 · CVSS v2 ⏱ Within 7 days
Enfold Theme - Unspecified Security Vulnerability

The Enfold theme has a documented security flaw, though specific details are limited. This is an older vulnerability from 2014 that should have been patched long ago.

Impact: The risk depends on the specific nature of the flaw, but any unpatched vulnerability leaves your site exposed to potential exploitation.

↗ View on NVD

Additional Vulnerabilities (71 more)

Showing first 10 of 71. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2023-0088 HIGH 8.8 2023-01-05 The Swifty Page Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validat…
CVE-2023-3343 HIGH 8.8 2023-07-13 The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1 via deserialization of untrusted input from the 'profile-p…
CVE-2023-6967 HIGH 8.8 2024-04-09 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to SQL Injection via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.…
CVE-2023-6999 HIGH 8.8 2024-04-09 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and including, 3.0.10 (with the except…
CVE-2024-11816 HIGH 8.8 2025-01-08 The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Remote Code Execution in version 3.0.11. This is due to a missing capability check on the 'wpext…
CVE-2025-14397 HIGH 8.8 2025-12-13 The Postem Ipsum plugin for WordPress is vulnerable to unauthorized modification of data to Privilege Escalation due to a missing capability check on the postem_ipsum_generate_use…
CVE-2024-13556 HIGH 8.1 2025-02-18 The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.1 …
CVE-2023-4278 HIGH 7.5 2023-09-11 The MasterStudy LMS WordPress Plugin WordPress plugin before 3.0.18 does not have proper checks in place during registration allowing anyone to register on the site as an instruct…
CVE-2024-11460 HIGH 7.5 2024-12-06 The Verowa Connect plugin for WordPress is vulnerable to SQL Injection via the 'search_string' parameter in all versions up to, and including, 3.0.1 due to insufficient escaping o…
CVE-2024-13184 HIGH 7.5 2025-01-18 The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to time-based SQL Injection via the Login Attempts module in all versions up to, and including,…
Full Report Available

All 77 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 3.0.1?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

Running WordPress 3.0.1 exposes your website to 77 known security vulnerabilities, including critical flaws that allow code injection, SQL injection, arbitrary file uploads, and privilege escalation attacks. These aren't theoretical risks—hackers actively exploit these known weaknesses to compromise sites, steal customer data, and deploy ransomware. The good news is that updating to the latest WordPress version eliminates most of these vulnerabilities immediately, and modern security practices keep your site protected going forward.

Don't wait for a breach to happen. Use SiteRecipe.com's comprehensive security scanning tools to identify all vulnerabilities on your WordPress site, prioritize critical fixes, and get step-by-step guidance to harden your security. Our platform scans for CVEs, outdated plugins, weak configurations, and malware—giving you complete visibility into your site's security posture. Start your free security audit at SiteRecipe.com today and protect your business from cyber attacks.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com