Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 3.1
Security Advisory

WordPress 3.1 Security: 538 CVEs Found – Update Now

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
1 websites still running wordpress 3.1  → View full list
538
Total
49
Critical
98
High
383
Medium
8
Low

WordPress 3.1 is an extremely outdated version released over a decade ago, and it poses a serious security risk to any website still running it. Our security research has identified 538 known vulnerabilities in this version, including 49 critical-level flaws that could allow attackers to take complete control of your website. If you're running WordPress 3.1, your site is likely already a target for hackers and malicious bots scanning the internet for vulnerable installations.

The vulnerabilities range from SQL injection attacks that could expose your entire database to PHP object injection flaws that enable remote code execution. Popular plugins commonly used with older WordPress versions—like Dokan Pro, GiveWP, Store Locator, and others—contain exploits that attackers actively use to compromise websites. Continuing to operate on WordPress 3.1 puts your business data, customer information, and reputation at severe risk.

This guide will help you identify if you're running this vulnerable version and provide clear steps to upgrade and secure your WordPress installation immediately.

What is Wordpress 3.1?

WordPress 3.1 is an ancient version of the world's most popular website-building platform, released in February 2011. At that time, it was considered modern and secure, but over the past 13+ years, thousands of security vulnerabilities have been discovered not only in WordPress itself but in the plugins and themes that extend its functionality. WordPress 3.1 lacks all the security patches, performance improvements, and modern features that have been added in subsequent versions.

Think of WordPress 3.1 like an old house with broken locks and no security system—it might have worked fine when it was built, but it's now extremely vulnerable to break-ins. Every day, hackers use automated tools to find websites running outdated WordPress versions and exploit known vulnerabilities to steal data, inject malware, or use the site to attack other websites. Running WordPress 3.1 in 2024 is essentially leaving your front door wide open to cybercriminals.

Key Vulnerabilities in Wordpress 3.1

538 CVEs found. The most critical are explained below.

CRITICAL CVE-2024-3922 10.0/10 · CVSS v3.1 ⏱ Immediate
Dokan Pro Plugin Database Attack Vulnerability

The Dokan Pro plugin has a serious flaw that allows hackers to manipulate your website's database without logging in. Attackers can exploit this through a specific setting called the 'code' parameter that wasn't properly secured.

Impact: Attackers could steal customer data, modify product information, access sensitive business records, or completely corrupt your database.

↗ View on NVD
CRITICAL CVE-2024-5932 10.0/10 · CVSS v3.1 ⏱ Immediate
GiveWP Donation Plugin Code Injection Risk

The GiveWP donation plugin contains a vulnerability where hackers can inject malicious code through the donation title field. This code runs directly on your server without needing login credentials.

Impact: Attackers could take control of your website, steal donor information, insert malware, or redirect visitors to malicious sites.

↗ View on NVD
CRITICAL CVE-2014-8621 9.8/10 · CVSS v3.0 ⏱ Immediate
Store Locator Plugin Database Manipulation

The Store Locator plugin versions 2.3-3.11 allow attackers to directly access and manipulate your website's database through the 'sl_custom_field' parameter. This is an old vulnerability that still affects many sites.

Impact: Criminals could extract customer lists, business data, or modify store location information displayed to visitors.

↗ View on NVD
CRITICAL CVE-2017-16949 9.8/10 · CVSS v3.0 ⏱ Immediate
Anonymous Post Plugin File Upload Security Bypass

The AccessPress Anonymous Post Pro plugin fails to properly validate file uploads, allowing attackers to upload dangerous files that bypass your security restrictions. They can override your file type and size limitations.

Impact: Hackers could upload malware, scripts, or ransomware to your server, potentially compromising your entire website and server.

↗ View on NVD
CRITICAL CVE-2014-5014 9.8/10 · CVSS v3.0 ⏱ Immediate
Flash Uploader Plugin Command Execution Flaw

The WordPress Flash Uploader plugin contains a critical flaw in how it handles image processing settings. Attackers can manipulate these settings to execute arbitrary commands on your server.

Impact: Attackers could gain full control of your website server, steal files, install backdoors, or use your server for other attacks.

↗ View on NVD
CRITICAL CVE-2019-13413 9.8/10 · CVSS v3.1 ⏱ Immediate
Rencontre Plugin Database Injection Attack

The Rencontre plugin has a flaw in its widget code that allows attackers to inject commands directly into your database without authentication. This happens through improper input validation in the plugin's widget functionality.

Impact: Attackers could steal user profiles, member information, or completely alter your website's content and functionality.

↗ View on NVD

Additional Vulnerabilities (532 more)

Showing first 10 of 532. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2019-15659 CRITICAL 9.8 2019-08-27 The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.
CVE-2015-9435 CRITICAL 9.8 2019-09-26 The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers.
CVE-2020-6009 CRITICAL 9.8 2020-04-01 LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection.
CVE-2021-24375 CRITICAL 9.8 2021-07-06 Lack of authentication or validation in motor_load_more, motor_gallery_load_more, motor_quick_view and motor_project_quick_view AJAX handlers of the Motor WordPress theme before 3…
CVE-2021-34621 CRITICAL 9.8 2021-07-07 A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register…
CVE-2021-34622 CRITICAL 9.8 2021-07-07 A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it possible for users to escalat…
CVE-2021-34623 CRITICAL 9.8 2021-07-07 A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitra…
CVE-2021-34624 CRITICAL 9.8 2021-07-07 A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary…
CVE-2022-1020 CRITICAL 9.8 2022-04-18 The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (av…
CVE-2022-0769 CRITICAL 9.8 2022-04-25 The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then execute…
Full Report Available

All 538 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 3.1?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 3.1 is dangerously outdated and puts your website at extreme risk of compromise. With 538 known vulnerabilities—including 49 critical flaws affecting SQL injection, file uploads, and remote code execution—staying on this version is not a matter of if your site will be hacked, but when. The upgrade process is straightforward and essential for protecting your business, your customers, and your reputation.

Don't wait for a security breach to force you into action. Use SiteRecipe.com's vulnerability scanner to continuously monitor your WordPress installation for security issues, outdated plugins, and configuration weaknesses. Our comprehensive security audits identify vulnerabilities before attackers do, and our expert guidance ensures your WordPress site stays secure, fast, and compliant. Visit SiteRecipe.com today to run a free security scan and take control of your website's protection.

Frequently Asked Questions

Why is WordPress 3.1 no longer supported?
WordPress 3.1 reached end-of-life in 2012, meaning it no longer receives security patches or updates from the WordPress development team. With over a decade of new vulnerabilities discovered since then, it's impossible to secure WordPress 3.1 without upgrading to a modern version that receives regular security updates.
Will updating to a newer WordPress version break my website?
While there's always a small risk of compatibility issues, the vast majority of websites update without problems, especially when you follow proper backup and testing procedures. The security benefits of updating far outweigh the minimal risk, and our guide above provides steps to minimize any issues.
Can I fix the vulnerabilities without upgrading WordPress?
No. The only way to truly protect yourself from WordPress 3.1's vulnerabilities is to upgrade to a current version. Security patches are not available for outdated versions, and attempting to 'work around' vulnerabilities is unreliable and time-consuming. Upgrading is the only safe solution.
How often should I check for new vulnerabilities?
You should monitor your WordPress installation continuously for new vulnerabilities as they're discovered almost weekly. SiteRecipe.com's automated scanning checks your site regularly and alerts you to any new threats, ensuring you stay ahead of potential security issues.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com