Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 3.2.1
Security Advisory

WordPress 3.2.1: 71 CVEs Found - Urgent Security Update

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
28 websites still running wordpress 3.2.1  → View full list
71
Total
2
Critical
14
High
55
Medium

WordPress 3.2.1 is an outdated version that contains 71 known security vulnerabilities, including 2 critical flaws that could compromise your entire website. If you're still running this ancient version, your site is at serious risk of being hacked, having malware injected, or experiencing data breaches. This guide will help you identify if you're vulnerable and take immediate action to protect your business.

Our security research team discovered that 28 websites are still using this vulnerable version, making them prime targets for cybercriminals. The vulnerabilities range from SQL injection attacks that can steal your database to file upload exploits that allow attackers to run malicious code on your server. Every day you wait increases the risk of a devastating security incident.

What is Wordpress 3.2.1?

WordPress 3.2.1 is an extremely outdated version of WordPress, the world's most popular website platform. Released over a decade ago, this version is no longer supported by the WordPress security team, meaning new vulnerabilities are discovered regularly but never patched. Running such an old version is like leaving your front door unlocked—attackers know exactly where to look for security holes.

When WordPress was at version 3.2.1, the internet looked completely different. This version lacks modern security features, doesn't have protection against sophisticated attacks, and relies on plugins that themselves contain dangerous flaws. The longer you stay on this version, the more likely your site will be targeted by automated hacking tools that specifically exploit these well-known vulnerabilities.

Key Vulnerabilities in Wordpress 3.2.1

71 CVEs found. The most critical are explained below.

CRITICAL CVE-2018-20973 9.8/10 · CVSS v3.0 ⏱ Immediate
Companion Auto-Update Plugin File Access Flaw

The Companion Auto-Update plugin has a security weakness that allows hackers to access files on your server they shouldn't be able to see. This happens through a technique called 'local file inclusion' where attackers can request sensitive files directly.

Impact: Attackers could read your configuration files containing database passwords, user information, and other sensitive data that could compromise your entire website.

↗ View on NVD
CRITICAL CVE-2019-14314 9.8/10 · CVSS v3.0 ⏱ Immediate
NextGEN Gallery Plugin Database Injection Attack

The Imagely NextGEN Gallery plugin contains a SQL injection vulnerability, which is like leaving a door open to your database. Hackers can write malicious commands that directly manipulate your website's database.

Impact: Attackers could steal all your website data, modify content, create fake admin accounts, or completely corrupt your database without needing to log in.

↗ View on NVD
HIGH CVE-2019-14216 8.8/10 · CVSS v3.0 ⏱ Immediate
WP SVG Icons Plugin Malicious Upload Vulnerability

The WP SVG Icons plugin allows hackers to trick website administrators into uploading dangerous files disguised as icon files. The plugin doesn't properly validate what files can be uploaded.

Impact: Attackers could upload hidden code that gives them control over your website, allowing them to steal data, redirect visitors, or take the site offline completely.

↗ View on NVD
HIGH CVE-2018-20972 8.8/10 · CVSS v3.0 ⏱ Immediate
Companion Auto-Update Plugin Admin Action Flaw

The Companion Auto-Update plugin lacks CSRF (Cross-Site Request Forgery) protection, meaning hackers can trick logged-in administrators into performing unauthorized actions without their knowledge.

Impact: Without your permission, attackers could change plugin settings, install malicious code, or modify your website's critical configurations through your own admin account.

↗ View on NVD
HIGH CVE-2021-39317 8.8/10 · CVSS v3.1 ⏱ Immediate
AccessPress Themes Unauthorized File Upload Flaw

AccessPress Themes plugins have a missing security check that fails to verify if someone should be allowed to upload files. This is like having a security guard who doesn't check credentials at the door.

Impact: Any visitor could upload malicious files to your server and execute code, giving them the ability to take over your website completely.

↗ View on NVD
HIGH CVE-2021-24804 8.8/10 · CVSS v3.1 ⏱ Immediate
Simple JWT Login Plugin Settings Modification Flaw

The Simple JWT Login plugin doesn't properly verify that an administrator actually intended to change security settings. Hackers can trick admins into unknowingly changing critical security configurations.

Impact: Attackers could change your login security settings, disable account verification, or promote attacker accounts to admin level, leading to complete website takeover.

↗ View on NVD

Additional Vulnerabilities (65 more)

Showing first 10 of 65. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2023-2628 HIGH 8.8 2023-06-27 The KiviCare WordPress plugin before 3.2.1 does not have CSRF checks (either flawed or missing completely) in various AJAX actions, which could allow attackers to make logged in u…
CVE-2024-5343 HIGH 8.8 2024-06-19 The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.19. This is due t…
CVE-2025-14844 HIGH 8.2 2026-01-16 The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 3.2.16 via the 'rcp_stripe_create_setup…
CVE-2024-12313 HIGH 8.1 2025-01-07 The Compare Products for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.1 via deserialization of untrusted input …
CVE-2026-1321 HIGH 8.1 2026-03-05 The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.20. This is due to the `rcp_setup_reg…
CVE-2018-20980 HIGH 7.5 2019-08-22 The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering.
CVE-2024-11939 HIGH 7.5 2025-01-08 The Cost Calculator Builder PRO plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘data’ parameter in all versions up to, and including, 3.2.15 due to i…
CVE-2025-12707 HIGH 7.5 2026-02-19 The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all versions up to, and including, 3.2.1 due to insufficient escaping …
CVE-2021-24483 HIGH 7.2 2021-08-02 The get_poll_categories(), get_polls() and get_reports() functions in the Poll Maker WordPress plugin before 3.2.1 did not use whitelist or validate the orderby parameter before u…
CVE-2024-9504 HIGH 7.2 2024-11-26 The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.2.1…
Full Report Available

All 71 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 3.2.1?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 3.2.1 is dangerously outdated and puts your business at extreme risk. With 71 known vulnerabilities including critical SQL injection and file upload flaws, staying on this version is essentially inviting hackers into your website. The good news is that updating is straightforward and takes less than an hour—far less time than recovering from a security breach would take.

Don't wait for a breach to happen. Use SiteRecipe.com to scan your website right now and identify all security vulnerabilities, outdated software, and potential attack vectors. Our platform will give you a detailed security report and step-by-step remediation guidance. Sign up for a free scan today and get peace of mind knowing your website is protected against the threats targeting WordPress 3.2.1 users.

Frequently Asked Questions

Will updating WordPress delete my posts and pages?
No, updating WordPress only upgrades the core software—all your content, pages, posts, and settings remain exactly as they are. Your backup ensures you can restore everything if something goes wrong during the update process.
What if I can't update WordPress 3.2.1 due to plugin compatibility?
If older plugins break after updating, you'll need to find modern alternatives. However, staying on a vulnerable version for plugin compatibility is much worse—you're trading one problem for a critical security disaster. Most plugins have been updated to work with current WordPress versions.
How often should I update WordPress after upgrading from 3.2.1?
WordPress releases security updates frequently, so you should enable automatic updates for both WordPress core and all plugins. This ensures you're always protected against newly discovered vulnerabilities without having to manually update constantly.
Can attackers see my WordPress version number?
Yes, attackers can easily detect your WordPress version through your website's source code and HTTP headers. This is why running an obviously outdated version like 3.2.1 makes you a target—they know exactly which exploits will work against you.
What should I do if my site was already hacked due to WordPress 3.2.1 vulnerabilities?
You need professional help immediately. Contact your hosting provider's security team, change all passwords, remove malicious files, and scan thoroughly with SiteRecipe.com. After cleaning, update WordPress and all plugins, then implement security hardening measures to prevent re-infection.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com