Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 3.1.2
Security Advisory

WordPress 3.1.2: 49 Critical Vulnerabilities Explained

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
11 websites still running wordpress 3.1.2  → View full list
49
Total
2
Critical
13
High
33
Medium
1
Low

WordPress 3.1.2 contains a dangerous collection of 49 security vulnerabilities that put your website at serious risk. Among these threats are 2 critical-level CVEs and 13 high-severity issues that attackers actively exploit. If you're still running this outdated version, your site could be compromised through SQL injection, unauthorized access, and path traversal attacks.

This comprehensive guide will help you understand the specific threats targeting WordPress 3.1.2, identify whether your site is vulnerable, and provide step-by-step instructions to secure your installation. With 11 websites still using this version, the threat is real and immediate action is necessary.

What is Wordpress 3.1.2?

WordPress 3.1.2 is an extremely outdated version of the world's most popular website platform, released over a decade ago. This version was surpassed by numerous major updates and security patches, making it one of the most vulnerable versions still in use today. Running WordPress 3.1.2 means your site lacks all the modern security features, performance improvements, and compatibility updates that come with current versions.

The version number itself indicates how far behind this installation is: current WordPress versions are in the 6.x range. WordPress 3.1.2 cannot receive security updates, is incompatible with modern plugins and themes, and exposes your website to every known vulnerability from that era plus new attacks discovered since its release. Continuing to use this version is like leaving your front door wide open to cybercriminals.

Key Vulnerabilities in Wordpress 3.1.2

49 CVEs found. The most critical are explained below.

CRITICAL CVE-2019-15659 9.8/10 · CVSS v3.0 ⏱ Immediate
Pie Register Plugin Database Attack

The Pie Register plugin has a serious flaw that allows attackers to directly access your WordPress database without proper authorization. This is a SQL injection vulnerability, which means hackers can write malicious code to steal or manipulate your website data.

Impact: Attackers could steal customer information, user passwords, and sensitive business data stored in your database, or modify your website content without permission.

↗ View on NVD
CRITICAL CVE-2022-1020 9.8/10 · CVSS v3.1 ⏱ Immediate
WooCommerce Product Table Missing Security Checks

The Product Table for WooCommerce plugin lacks important security verification steps in its settings. This means anyone—even people not logged into your site—can make unauthorized changes to your plugin settings and inject malicious code.

Impact: Attackers could modify your product pages, inject malware, or redirect your customers to phishing sites without needing to log in to your website.

↗ View on NVD
HIGH CVE-2023-23490 8.8/10 · CVSS v3.1 ⏱ Within 7 days
Survey Maker Plugin Database Injection Flaw

The Survey Maker plugin allows logged-in users to inject malicious SQL commands through survey export features. An authenticated attacker can manipulate the database by inserting extra commands into normal survey operations.

Impact: Attackers with user access could steal survey data, modify records, or extract sensitive information from your WordPress database without triggering obvious alarms.

↗ View on NVD
HIGH CVE-2023-1615 8.8/10 · CVSS v3.1 ⏱ Within 7 days
Contact Form 7 Ultimate Addons SQL Injection

The Ultimate Addons for Contact Form 7 plugin has a flaw that allows any logged-in user to inject unauthorized database commands through the form ID parameter. These extra commands execute alongside legitimate database queries.

Impact: Even low-privilege users (like form managers) could access restricted customer data, delete records, or modify sensitive information in your forms and database.

↗ View on NVD
HIGH CVE-2025-32629 8.6/10 · CVSS v3.1 ⏱ Immediate
Business Directory Plugin File Access Vulnerability

The WP-BusinessDirectory plugin has a path traversal flaw that allows attackers to access files and folders outside their intended directory. This is like someone finding a secret passage to explore restricted areas of your website's file system.

Impact: Attackers could access sensitive configuration files containing database passwords, API keys, or other private data needed to fully compromise your website.

↗ View on NVD
HIGH CVE-2023-6964 8.5/10 · CVSS v3.1 ⏱ Within 7 days
Kadence Blocks Plugin Server Attack Vulnerability

The Gutenberg Blocks by Kadence plugin allows authenticated users to make your server fetch data from external websites they control. This Server-Side Request Forgery (SSRF) flaw tricks your server into performing actions it shouldn't.

Impact: Attackers could use your server to attack other websites, access internal services, or gather information about your network infrastructure that could lead to further attacks.

↗ View on NVD

Additional Vulnerabilities (43 more)

Showing first 10 of 43. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2025-9693 HIGH 8.0 2025-09-11 The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the postI…
CVE-2021-34639 HIGH 7.5 2021-08-05 Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. "payload.php.png" which is exe…
CVE-2021-24860 HIGH 7.2 2021-11-29 The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before using them in a SQL statement, leading to a SQL injection is…
CVE-2021-25064 HIGH 7.2 2022-03-28 The Wow Countdowns WordPress plugin through 3.1.2 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection.
CVE-2022-33970 HIGH 7.2 2022-07-27 Authenticated WordPress Options Change vulnerability in Biplob018 Shortcode Addons plugin <= 3.1.2 at WordPress.
CVE-2023-0084 HIGH 7.2 2023-03-02 The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via text areas on forms in versions up to, and including, 3.1.2 due to…
CVE-2021-4358 HIGH 7.2 2023-06-07 The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 3.1.23 due to insufficient i…
CVE-2016-15041 HIGH 7.2 2024-10-16 The MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mwp_setup_purchase…
CVE-2025-32630 HIGH 7.1 2025-04-17 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CMSJunkie - WordPress Business Directory Plugins WP-BusinessDirectory wp-busi…
CVE-2015-4336 MEDIUM 6.5 2015-06-17 cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary commands via a file containing filenames with shell metachara…
Full Report Available

All 49 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 3.1.2?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 3.1.2 is dangerously outdated and should never run a live website. The 49 vulnerabilities, especially the 2 critical CVEs allowing SQL injection and unauthorized access, make this version a prime target for attackers. Upgrading to the latest WordPress version is not optional—it's essential for protecting your data, your visitors' information, and your business reputation.

Don't wait for a breach to force your hand. Use SiteRecipe.com's comprehensive vulnerability scanner today to identify all security threats on your website, get detailed remediation guidance, and monitor your site's security ongoing. Our platform makes it simple to check your WordPress version, understand your vulnerabilities, and fix them fast. Visit SiteRecipe.com now and take control of your website security.

Frequently Asked Questions

Is WordPress 3.1.2 still supported with security updates?
No. WordPress 3.1.2 reached end-of-life years ago and receives no official security patches whatsoever. Any vulnerability discovered in this version will never be fixed by WordPress, leaving your site permanently exposed to known attacks that attackers actively exploit.
What is SQL injection and why is it dangerous in these CVEs?
SQL injection allows attackers to manipulate your database queries by injecting malicious code. In WordPress 3.1.2's critical CVEs, attackers can execute unauthorized SQL commands to steal your entire database containing user credentials, content, and sensitive information without needing valid login credentials.
Can I update just WordPress core without updating plugins?
Yes, but you should update everything eventually. Upgrade WordPress core first to patch the critical vulnerabilities, then systematically update plugins and themes. Many plugins may not work with WordPress 3.1.2 anyway, so updating gives you access to modern, compatible extensions that your site likely needs.
What if my site breaks after upgrading from WordPress 3.1.2?
This is why backups are crucial before upgrading. If something breaks, restore from your backup immediately. However, most issues stem from outdated plugins—after restoring, update your plugins to versions compatible with the latest WordPress, or find modern alternatives that support current WordPress versions.
How can SiteRecipe.com help protect my WordPress site?
SiteRecipe.com continuously scans your WordPress installation to identify vulnerabilities like those in version 3.1.2, provides detailed explanations of each threat, and offers actionable remediation steps. Our scanner confirms when you've successfully patched vulnerabilities and alerts you to new threats automatically.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com