Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 3.4.2
Security Advisory

WordPress 3.4.2: 44 CVEs Found - Critical Security Issues

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
61 websites still running wordpress 3.4.2  → View full list
44
Total
2
Critical
9
High
30
Medium
3
Low

WordPress 3.4.2 contains 44 known security vulnerabilities, including 2 critical-severity flaws that could allow attackers to take over your website. If your site still runs this outdated version, you're at serious risk of compromise through path traversal attacks, privilege escalation, and SQL injection exploits. This guide explains what these vulnerabilities mean for your website and how to fix them immediately.

Our analysis reveals that 61 websites are currently exposed to these threats. The most dangerous vulnerabilities include the Hummingbird plugin's path traversal flaw and the Branda plugin's account takeover vulnerability. Even if you think you're protected, plugin vulnerabilities can bypass your main WordPress security measures.

The good news is that updating is straightforward. We'll walk you through identifying if you're vulnerable, understanding the risks, and implementing fixes that take just minutes to complete.

What is Wordpress 3.4.2?

WordPress 3.4.2 is an older version of the WordPress content management system, released several years ago. It's the software that powers the backend of your website, allowing you to create pages, publish posts, manage users, and control how your site looks and functions. Think of it as the foundation of your website—everything you do relies on it working properly and securely.

This specific version (3.4.2) is no longer supported by WordPress developers, meaning it doesn't receive security updates or bug fixes anymore. When WordPress versions become outdated, hackers actively target them because they know about the vulnerabilities and can exploit websites still using the old code. Running WordPress 3.4.2 is like leaving your front door unlocked in a neighborhood where thieves know which houses have old locks.

Key Vulnerabilities in Wordpress 3.4.2

44 CVEs found. The most critical are explained below.

CRITICAL CVE-2023-1478 9.8/10 · CVSS v3.1 ⏱ Immediate
Hummingbird Plugin Cache File Vulnerability

The Hummingbird caching plugin has a flaw that allows attackers to write files in unintended locations on your server. This happens because the plugin doesn't properly check where cached files are being saved before creating them.

Impact: An attacker could place malicious files on your server, potentially taking control of your website or stealing sensitive data.

↗ View on NVD
CRITICAL CVE-2025-14998 9.8/10 · CVSS v3.1 ⏱ Immediate
Branda Plugin Account Takeover Vulnerability

The Branda plugin allows anyone to change user passwords without verifying they actually own the account. An attacker doesn't need to be logged in to exploit this vulnerability.

Impact: Attackers could take over any user account on your site, including administrator accounts, giving them complete control of your website.

↗ View on NVD
HIGH CVE-2024-2025 8.8/10 · CVSS v3.1 ⏱ Immediate
BuddyPress WooCommerce Plugin Code Injection

The BuddyPress WooCommerce plugin improperly processes certain data, allowing attackers to inject harmful code into your website. This happens when the plugin deserializes untrusted information.

Impact: An attacker could execute malicious code on your website, potentially stealing customer data, inserting spam, or taking control of your site.

↗ View on NVD
HIGH CVE-2023-6360 8.6/10 · CVSS v3.1 ⏱ Immediate
My Calendar Plugin Database Access Vulnerability

The My Calendar plugin has a flaw that lets anyone access your database directly without logging in. Attackers can manipulate search parameters to retrieve sensitive information.

Impact: Attackers could steal all event data and any private information stored in your database without needing a password.

↗ View on NVD
HIGH CVE-2021-24197 8.1/10 · CVSS v3.1 ⏱ Within 7 days
wpDataTables Unauthorized Data Access

The wpDataTables plugin doesn't properly check who is allowed to view data in tables. A logged-in user can manipulate settings to see another user's private data from the same table.

Impact: Your users' private information displayed in tables could be exposed to other users who shouldn't have access to it.

↗ View on NVD
HIGH CVE-2021-24198 8.1/10 · CVSS v3.1 ⏱ Within 7 days
wpDataTables Unauthorized Data Deletion

The wpDataTables plugin fails to properly verify permissions before allowing data deletion. A logged-in user can delete another user's data by changing table parameters.

Impact: Important data in your tables could be permanently deleted by users who shouldn't have permission to make those changes.

↗ View on NVD

Additional Vulnerabilities (38 more)

Showing first 10 of 38. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2021-24636 HIGH 8.1 2021-09-20 The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks, which allows attackers to make logged in administrators deactivate the Print My Blog plugin a…
CVE-2021-24739 HIGH 8.1 2021-12-21 The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by other users via the Carousel D…
CVE-2025-9048 HIGH 8.1 2025-08-23 The Wptobe-memberships plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the del_img_ajax_call() function in all versions u…
CVE-2021-24651 HIGH 7.5 2021-10-11 The Poll Maker WordPress plugin before 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_poll AJAX action. While the result is not disclosed in the re…
CVE-2023-6222 HIGH 7.2 2023-12-18 IThe Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 does not validate user input used in a path, which could allow users with an admin role to perform path traversal …
CVE-2012-4448 MEDIUM 6.8 2012-09-28 Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that m…
CVE-2020-36174 MEDIUM 6.5 2021-01-06 The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration.
CVE-2021-24199 MEDIUM 6.5 2021-04-12 The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table …
CVE-2021-24200 MEDIUM 6.5 2021-04-12 The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table …
CVE-2022-3926 MEDIUM 6.5 2022-12-05 The WP OAuth Server (OAuth Authentication) WordPress plugin before 3.4.2 does not have CSRF check when regenerating secrets, which could allow attackers to make logged in admins r…
Full Report Available

All 44 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 3.4.2?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 3.4.2 poses an unacceptable security risk with 44 known vulnerabilities ready to be exploited. The two critical-severity flaws alone could lead to complete website compromise, data theft, or malware installation. Delaying this update puts your business, customer data, and reputation in danger. The update process takes less than 30 minutes and is essential maintenance, not optional.

Use SiteRecipe.com's security scanning tools to identify all vulnerabilities on your website and monitor for future threats. Our platform continuously checks for CVEs, outdated versions, and misconfigurations, alerting you before attackers find them. Stop worrying about security—let SiteRecipe automate your vulnerability management and keep your WordPress site protected 24/7.

Frequently Asked Questions

What happens if I don't update from WordPress 3.4.2?
Your website becomes increasingly vulnerable to automated attacks targeting these 44 known vulnerabilities. Hackers use tools that scan the internet for outdated WordPress versions and exploit them within minutes of discovery. You risk complete website compromise, customer data theft, malware installation, and blacklisting from search engines—potentially costing thousands in recovery.
Will updating to the latest WordPress break my website?
Most updates are seamless, but compatibility issues can occur with very old plugins or custom code. That's why we recommend backing up first and testing updates on a staging copy of your site if possible. Modern WordPress is designed to be backward-compatible, and the update process is automated—WordPress handles most technical details for you.
What is a path traversal vulnerability and why is it dangerous?
Path traversal (also called directory traversal) allows attackers to access files and directories outside the intended folder. In the CVE-2023-1478 Hummingbird vulnerability, an attacker could write malicious code to any location on your server, potentially taking complete control. It's like someone bypassing your house's front lock to access all rooms, including your safe.
Can I update WordPress without losing my posts and settings?
Yes, absolutely. WordPress updates preserve all your content, settings, user accounts, and plugin data. The update only changes the core WordPress software files. Your posts, pages, comments, and database remain completely intact. This is why WordPress updates are safe—they're designed to never delete or modify your data.
How often should I update WordPress after fixing this?
Update WordPress immediately whenever a new version is released, especially for security updates. Check your WordPress dashboard weekly for update notifications. Most modern hosting providers can enable automatic updates. After you're current with version 6.x, you'll receive updates much more frequently (usually monthly), making your site significantly more secure.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com