Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 3.4
Security Advisory

WordPress 3.4 Security: 226 CVEs Explained & Fixed

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
9 websites still running wordpress 3.4  → View full list
226
Total
10
Critical
37
High
176
Medium
3
Low

WordPress 3.4 is an outdated version released over a decade ago, yet surprisingly, 9 websites still run this vulnerable software. Our security analysis identified 226 known vulnerabilities affecting this version, including 10 critical exploits that could compromise your entire website, steal customer data, or inject malware. These aren't theoretical threats—cybercriminals actively exploit these weaknesses daily.

If your business relies on WordPress 3.4, you're operating with a massive security liability. This guide explains the specific threats you face, how to identify if you're vulnerable, and the exact steps to protect your site before hackers strike. Time is critical: every day your site remains on this version increases the risk of a successful breach.

What is Wordpress 3.4?

WordPress 3.4 was released in 2012 and reached end-of-life years ago. Think of it like driving a car from 2012 without any safety updates—the basic engine still works, but it lacks modern protections against sophisticated threats. WordPress 3.4 powered millions of websites in its day, but security standards have evolved dramatically since then. Modern WordPress versions include automatic security patches, improved authentication methods, and hardened code against common attack vectors that didn't exist when 3.4 was developed.

Running WordPress 3.4 today is like leaving your front door unlocked with a neon sign advertising your negligence. The platform itself isn't inherently bad, but it's simply incompatible with current cybersecurity threats. Hackers use automated tools to scan the internet for outdated WordPress installations and exploit known weaknesses within seconds. Without regular security updates, your site becomes a sitting duck for SQL injection attacks, unauthorized admin access, file inclusion exploits, and malware injection—all of which are documented threats against WordPress 3.4.

Key Vulnerabilities in Wordpress 3.4

226 CVEs found. The most critical are explained below.

CRITICAL CVE-2019-14695 9.8/10 · CVSS v3.1 ⏱ Immediate
Sygnoos Popup Builder - Database Attack Vulnerability

A flaw in the Sygnoos Popup Builder plugin allows hackers to directly access and manipulate your website's database. This happens through the table sorting feature, which doesn't properly filter user input before sending commands to your database.

Impact: An attacker could steal your customer data, modify website content, or completely compromise your database without needing to log in.

↗ View on NVD
CRITICAL CVE-2021-24527 9.8/10 · CVSS v3.1 ⏱ Immediate
Profile Builder - Admin Account Takeover Risk

The Profile Builder plugin has a weakness in its password reset system that allows anyone to reset your admin password without permission. The plugin doesn't properly verify who is requesting the password reset.

Impact: A hacker could take over your entire website by resetting your admin password and logging in as you, giving them complete control.

↗ View on NVD
CRITICAL CVE-2021-24849 9.8/10 · CVSS v3.1 ⏱ Immediate
WCFM Marketplace - Database Injection Attack

The WCFM Marketplace plugin fails to clean up user input in its AJAX functions before using it in database queries. This allows both logged-in users and visitors to inject malicious code.

Impact: Attackers can access sensitive data, modify your marketplace listings, steal customer information, or sabotage your store's functionality.

↗ View on NVD
CRITICAL CVE-2023-1478 9.8/10 · CVSS v3.1 ⏱ Immediate
Hummingbird - File Writing Vulnerability

The Hummingbird plugin doesn't properly validate where it saves cached files, allowing attackers to write files to dangerous locations on your server. This is like leaving a door open for someone to place harmful files in critical system areas.

Impact: An attacker could place malicious files on your server to take control of your website, inject malware, or cause your site to crash.

↗ View on NVD
CRITICAL CVE-2023-5877 9.8/10 · CVSS v3.1 ⏱ Immediate
Affiliate Toolkit - Unprotected External Requests

The Affiliate Toolkit plugin has an endpoint that allows anyone on the internet to make requests without any password or permission check. Attackers can use this to access internal systems or private networks.

Impact: Hackers could use your website to attack other systems, access private company networks, or gather sensitive information about your infrastructure.

↗ View on NVD
CRITICAL CVE-2024-11642 9.8/10 · CVSS v3.1 ⏱ Immediate
Post Grid Master - Unauthorized File Access

The Post Grid Master plugin allows attackers to read files from your server that they shouldn't have access to. The vulnerability is in how the plugin locates and loads template files.

Impact: An attacker could access sensitive files like configuration files containing database passwords, API keys, or other confidential information.

↗ View on NVD

Additional Vulnerabilities (220 more)

Showing first 10 of 220. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2025-14998 CRITICAL 9.8 2026-01-02 The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.24. This is due to the plugin not properly val…
CVE-2026-3296 CRITICAL 9.8 2026-04-08 The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry met…
CVE-2026-8181 CRITICAL 9.8 2026-05-14 The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1…
CVE-2024-3412 CRITICAL 9.1 2024-05-29 The WP STAGING WordPress Backup Plugin – Migration Backup Restore plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wpstg_pro…
CVE-2017-9418 HIGH 8.8 2017-06-12 SQL injection vulnerability in the WP-Testimonials plugin 3.4.1 for WordPress allows an authenticated user to execute arbitrary SQL commands via the testid parameter to wp-admin/a…
CVE-2019-17661 HIGH 8.8 2019-11-08 A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to gain remote control of other computers. By choosing formula…
CVE-2019-17237 HIGH 8.8 2019-11-12 includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF.
CVE-2021-24163 HIGH 8.8 2021-04-05 The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, therefore making it possible for l…
CVE-2022-4935 HIGH 8.8 2023-04-05 The WCFM Marketplace plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 3.4.11 due to missing capability checks o…
CVE-2024-2025 HIGH 8.8 2024-03-23 The "BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages" plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includin…
Full Report Available

All 226 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 3.4?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 3.4 represents an unacceptable security risk in 2024. With 226 known vulnerabilities—10 of them critical—your website is vulnerable to SQL injection, unauthorized access, file inclusion attacks, and complete compromise. The good news: upgrading to a modern WordPress version is straightforward and protects your business, customers, and reputation.

Don't wait for a breach notification. SiteRecipe.com's advanced vulnerability scanner identifies outdated software, missing patches, and active exploits on your site in minutes. We'll show you exactly which vulnerabilities affect your WordPress installation and provide step-by-step remediation guidance. Start your free security scan today and stop operating in the cyber dark ages.

Frequently Asked Questions

Will upgrading WordPress 3.4 break my website?
Modern versions are backward-compatible with most functionality, but some very old custom code or plugins may not work. That's why we recommend testing on a staging environment first. SiteRecipe.com helps identify compatibility issues before you upgrade, so you know exactly what might need adjustment.
What's the worst that could happen if I don't upgrade?
Hackers could steal your customer database, inject malware that damages visitor computers, display unauthorized content, redirect traffic to scam sites, or completely take over your admin account. Each of the 10 critical CVEs can lead to complete website compromise and legal liability for exposing customer data.
How long does it take to upgrade from WordPress 3.4?
The core upgrade takes 15-30 minutes. Including plugin updates and testing, plan for 1-2 hours total. If you have custom code or many plugins, use SiteRecipe.com to audit compatibility first, which typically adds another 30 minutes but prevents costly mistakes during the upgrade process.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com