Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 3.5
Security Advisory

WordPress 3.5: 201 Critical Vulnerabilities Found - Update Now

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
25 websites still running wordpress 3.5  → View full list
201
Total
16
Critical
40
High
139
Medium
5
Low

WordPress 3.5, released in December 2012, is now a legacy version carrying severe security risks. Our security audit found 201 documented vulnerabilities affecting this outdated platform, including 16 critical-level flaws that could allow attackers to take complete control of your website. If you're still running this version, your site is in immediate danger of being hacked, having your data stolen, or being used to attack other websites.

The vulnerabilities range from Remote Code Execution attacks that let hackers run malicious commands on your server, to SQL injection flaws that expose your entire database. Popular plugins like Social Warfare, Smart Google Code Inserter, and Astra Pro Addon contain critical security holes specific to older WordPress versions. This guide will help you determine if you're vulnerable and show you exactly how to fix the problem.

What is Wordpress 3.5?

WordPress 3.5 is an extremely old version of WordPress, the platform that powers over 40% of all websites on the internet. It was released in 2012 and has been succeeded by dozens of newer versions. Like older software of any kind—whether it's operating systems, browsers, or applications—WordPress 3.5 no longer receives security updates from its developers. This means new security vulnerabilities discovered today will never be patched for version 3.5.

Think of WordPress 3.5 like driving a car from the 1980s without airbags, anti-lock brakes, or modern safety features. It might still run, but it's missing all the protective systems that modern vehicles have. Every day that passes, new security threats emerge that WordPress developers patch in current versions, but those fixes never reach version 3.5. This creates a widening security gap between your website and modern threats.

Key Vulnerabilities in Wordpress 3.5

201 CVEs found. The most critical are explained below.

CRITICAL CVE-2021-4434 10.0/10 · CVSS v3.1 ⏱ Immediate
Social Warfare Plugin - Attackers Can Run Code on Your Server

The Social Warfare plugin (versions up to 3.5.2) has a serious flaw that lets hackers run their own code directly on your website's server. This happens through a feature called 'swp_url' that doesn't properly check what data is being sent to it.

Impact: Attackers could take complete control of your website, steal customer data, install malware, send spam emails from your domain, or redirect visitors to malicious sites.

↗ View on NVD
CRITICAL CVE-2018-3810 9.8/10 · CVSS v3.0 ⏱ Immediate
Smart Google Code Inserter - Hackers Can Inject Malicious Code

The Oturia Smart Google Code Inserter plugin (before version 3.5) allows anyone on the internet to inject harmful code into your website without needing to log in. This code then runs on every page your visitors see.

Impact: Your website could display fake login forms to steal visitor credentials, inject advertisements, redirect users to scam sites, or spread malware to your visitors' computers.

↗ View on NVD
CRITICAL CVE-2018-3811 9.8/10 · CVSS v3.0 ⏱ Immediate
Smart Google Code Inserter - Database Hack Vulnerability

The same plugin has another critical flaw where attackers can send specially crafted requests to access your website's database without logging in. They can read, modify, or delete sensitive information stored there.

Impact: Hackers could steal all your customer information, payment details, user accounts, and any other data stored in your database, potentially exposing you to legal liability and loss of customer trust.

↗ View on NVD
CRITICAL CVE-2021-24507 9.8/10 · CVSS v3.1 ⏱ Immediate
Astra Pro Addon - Database Injection Vulnerability

The Astra Pro Addon plugin (before 3.5.2) has a flaw in its pagination features that allows attackers to send malicious requests to your database. The plugin doesn't properly validate this incoming data before using it.

Impact: Attackers could access, modify, or delete your database contents, including customer records, product information, and website configuration, without needing admin access.

↗ View on NVD
CRITICAL CVE-2021-24666 9.8/10 · CVSS v3.1 ⏱ Immediate
Podlove Podcast Publisher - Database Injection in Social Features

The Podlove Podcast Publisher plugin (before 3.5.6) has an optional Social & Donations module that doesn't properly validate contributor ID and category data before using it in database queries.

Impact: Attackers could exploit this to access or manipulate your database, steal listener information, or disrupt your podcast publishing functionality.

↗ View on NVD
CRITICAL CVE-2022-3477 9.8/10 · CVSS v3.1 ⏱ Immediate
tagDiv Composer - Fake Login Vulnerability

The tagDiv Composer plugin (before 3.5, required by Newspaper and Newsmag themes) has a broken Facebook login feature that allows anyone to log into any user account on your site if they know that person's email address.

Impact: Attackers could impersonate any user on your website, including administrators, and gain full control over content, settings, and sensitive information without knowing any password.

↗ View on NVD

Additional Vulnerabilities (195 more)

Showing first 10 of 195. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2021-24649 CRITICAL 9.8 2022-11-21 The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created w…
CVE-2022-3180 CRITICAL 9.8 2025-02-11 The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This allows unauthenticated attackers to create arbitrary malicious…
CVE-2024-13421 CRITICAL 9.8 2025-02-12 The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricti…
CVE-2025-1315 CRITICAL 9.8 2025-03-07 The InWave Jobs plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 3.5.1. This is due to the plugin not properly v…
CVE-2025-2505 CRITICAL 9.8 2025-03-20 The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 via the 'lang' parameter. This makes it possible for unauth…
CVE-2025-1562 CRITICAL 9.8 2025-06-18 The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to unauthorized arbitrary plugin instal…
CVE-2016-15043 CRITICAL 9.8 2025-07-19 The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in resize.php file in versions up to, and including, 3.5. T…
CVE-2025-15521 CRITICAL 9.8 2026-01-21 The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and i…
CVE-2026-34424 CRITICAL 9.8 2026-04-09 Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated …
CVE-2021-4374 CRITICAL 9.1 2023-06-07 The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to missing authorization and option v…
Full Report Available

All 201 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 3.5?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

Running WordPress 3.5 in 2024 is like leaving your front door unlocked with a sign saying 'no valuables inside'—it's simply not worth the risk. The 201 vulnerabilities we found, especially the 16 critical-level flaws, represent real threats that hackers actively exploit. Your website isn't just at risk of being defaced or taken offline; it could be silently compromised to steal customer data, send spam, or distribute malware to your visitors.

Don't wait for a breach to happen. Use SiteRecipe.com's free vulnerability scanner to identify exactly which CVEs affect your website, get step-by-step upgrade guidance, and ensure your WordPress installation is secure. Our tools help you understand your security posture and fix vulnerabilities before attackers find them. Visit SiteRecipe.com today to scan your website and take control of your security.

Frequently Asked Questions

Is WordPress 3.5 still getting security updates?
No. WordPress 3.5 reached end-of-life years ago and no longer receives any security patches. Developers only support the current and two previous major versions. Using WordPress 3.5 means you'll never receive fixes for newly discovered vulnerabilities, making your site increasingly vulnerable over time.
Can I update WordPress 3.5 directly to the latest version?
Yes, WordPress is designed to allow direct upgrades from very old versions to current releases. However, you should back up your site first, ensure your plugins and themes are compatible, and test thoroughly afterward. Some very old plugins may no longer work with modern WordPress versions.
What happens if I don't update WordPress 3.5?
Hackers actively scan the internet for outdated WordPress installations because they know exactly which exploits will work. Your site could be compromised to steal data, display malware, send spam emails, or be used to attack other websites. You may also face legal liability if customer data is stolen due to negligence.
How long does a WordPress update take?
A typical WordPress update takes 2-5 minutes and happens automatically. After updating, you should spend 10-15 minutes testing your site's critical functions. Most websites experience zero downtime during the update process.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com