Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 3.5.1
Security Advisory

WordPress 3.5.1: 48 CVEs Found - Security Guide 2024

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
131 websites still running wordpress 3.5.1  → View full list
48
Total
3
Critical
7
High
35
Medium
2
Low

WordPress 3.5.1 contains a staggering 48 known vulnerabilities, including 3 critical security flaws that could expose your website to complete compromise. Despite being an older version, 131 websites worldwide still run this vulnerable software, making them prime targets for cybercriminals. If your site is among them, immediate action is required.

Our security team has analyzed the top threats in WordPress 3.5.1, including privilege escalation attacks, remote code execution, and CSRF vulnerabilities. This comprehensive guide will help you identify if your website is at risk and provide step-by-step instructions to secure your installation before attackers strike.

What is Wordpress 3.5.1?

WordPress 3.5.1 is an older version of the world's most popular website platform, released years ago with outdated security standards. While it was once considered stable, technology evolves rapidly and new attack methods emerge constantly. This version lacks the modern security protections built into current WordPress releases, making it increasingly dangerous to operate in today's threat landscape.

Think of WordPress like a house: older homes may still function, but they lack modern security features like alarm systems and reinforced locks. WordPress 3.5.1 is that aging house—it might technically work, but it's vulnerable to intruders who know its weaknesses. The 48 documented vulnerabilities are like 48 different ways someone could break in, and hackers actively exploit these known entry points.

Key Vulnerabilities in Wordpress 3.5.1

48 CVEs found. The most critical are explained below.

CRITICAL CVE-2024-13421 9.8/10 · CVSS v3.1 ⏱ Immediate
Real Estate 7 Theme - Unauthorized Admin Registration

The Real Estate 7 theme allows anyone to register on your site and automatically assign themselves as an administrator during signup. Attackers can bypass normal registration rules and gain full control of your website without needing valid credentials.

Impact: Attackers could take over your entire website, access sensitive data, modify content, or use your site to spread malware to visitors.

↗ View on NVD
CRITICAL CVE-2025-1315 9.8/10 · CVSS v3.1 ⏱ Immediate
InWave Jobs Plugin - Password Reset Vulnerability

The InWave Jobs plugin allows anyone to reset and change any user's password without proof of identity. An attacker can take over accounts by simply resetting passwords, including administrator accounts.

Impact: Attackers can hijack any user account including yours, lock you out of your own site, and gain complete administrative access.

↗ View on NVD
CRITICAL CVE-2026-34424 9.8/10 · CVSS v3.1 ⏱ Immediate
Smart Slider 3 Pro - Malicious Update with Remote Access

Smart Slider 3 Pro's update system was compromised and injected with malware. When you update the plugin, attackers automatically gain remote access to execute any commands on your server.

Impact: Your entire server could be compromised, allowing attackers to steal data, install ransomware, or use your server for illegal purposes.

↗ View on NVD
HIGH CVE-2015-5483 8.8/10 · CVSS v3.1 ⏱ Within 7 days
Private Only Plugin - Administrator Actions Can Be Hijacked

The Private Only plugin has security flaws that allow attackers to trick administrators into performing unauthorized actions through forged requests. Attackers can add fake users, delete posts, or modify website files.

Impact: Your site could have unauthorized users added, important content deleted, or core website files changed without your knowledge or consent.

↗ View on NVD
HIGH CVE-2022-3357 8.8/10 · CVSS v3.1 ⏱ Within 7 days
Smart Slider 3 - Malicious File Import Vulnerability

Smart Slider 3 plugin doesn't properly check files you import. If you accidentally import a malicious file, attackers can inject harmful code into your website through PHP object injection.

Impact: Attackers could execute malicious code on your server if you import a compromised slider file, potentially compromising your entire site.

↗ View on NVD
HIGH CVE-2021-24893 7.5/10 · CVSS v3.1 ⏱ Within 30 days
Stars Rating Plugin - Denial of Service Attack

The Stars Rating plugin doesn't properly validate rating submissions. Attackers can submit extremely large numbers that crash your comments section or dashboard.

Impact: Your website's comments section or admin dashboard could become unusable, disrupting normal site operations and user experience.

↗ View on NVD

Additional Vulnerabilities (42 more)

Showing first 10 of 42. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2025-2186 HIGH 7.5 2025-03-22 The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for WordPress is vulnerable to SQL Injection via the ‘automationId’…
CVE-2025-7504 HIGH 7.5 2025-07-12 The Friends plugin for WordPress is vulnerable to PHP Object Injection in version 3.5.1 via deserialization of untrusted input of the query_vars parameter This makes it possible f…
CVE-2025-6220 HIGH 7.2 2025-06-18 The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_options' function in all versions…
CVE-2025-6212 HIGH 7.2 2025-06-26 The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Database module in versions 3.5.11 to 3.5.19 due to insufficient inpu…
CVE-2014-8603 MEDIUM 6.5 2015-06-10 cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code via shell metacharacters in the (1) fil…
CVE-2023-6077 MEDIUM 6.5 2023-12-18 The Slider WordPress plugin before 3.5.12 does not ensure that posts to be accessed via an AJAX action are slides and can be viewed by the user making the request, allowing any au…
CVE-2024-23517 MEDIUM 6.5 2024-02-10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Start Booking Scheduling Plugin – Online Booking for WordPress allows Stored …
CVE-2024-1634 MEDIUM 6.5 2024-06-18 The Scheduling Plugin – Online Booking for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'cbsb_disconnect_sett…
CVE-2026-3098 MEDIUM 6.5 2026-03-27 The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possi…
CVE-2013-0235 MEDIUM 6.4 2013-07-08 The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL f…
Full Report Available

All 48 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 3.5.1?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 3.5.1 is no longer safe to operate. With 3 critical vulnerabilities allowing remote code execution and privilege escalation, your website could be completely compromised within days. The good news is that updating is straightforward and takes just minutes—far less time than recovering from a security breach.

Don't become another statistic. Use SiteRecipe.com's comprehensive WordPress security scanning tools to identify all vulnerabilities on your site, get personalized remediation guidance, and monitor your installation continuously. Our platform catches security issues before attackers do. Start your free security audit today at SiteRecipe.com and protect your business from these critical threats.

Frequently Asked Questions

What does 'privilege escalation' mean for my website?
Privilege escalation means attackers can gain administrator-level access to your WordPress site without knowing the password. Once they have admin access, they can steal data, inject malware, deface your site, or lock you out completely. This is one of the most dangerous types of attacks.
Can I stay on WordPress 3.5.1 if I disable plugins?
No. The vulnerabilities exist in WordPress core itself, not just plugins. Even with all plugins disabled, your site remains vulnerable to attacks. The only safe solution is to update to a current WordPress version immediately.
Will updating WordPress delete my content or break my site?
Proper updates rarely cause problems if you follow best practices—backup first, update, then test. Most sites update smoothly. Even if something breaks, your backup ensures you can restore everything. The risk of not updating is far greater than the minimal risk of updating.
How long does WordPress updating take?
Most WordPress updates complete in under 5 minutes. Backing up your site first might take 10-30 minutes depending on site size, but both processes are straightforward. Compare this to potential weeks of downtime from a security breach.
Are there any themes or plugins I should avoid with newer WordPress versions?
Very old themes and plugins designed specifically for WordPress 3.5.1 may not work with current versions, but this is actually good—it forces you to use modern, supported software. Most well-built themes and plugins are backward-compatible and will work perfectly.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com