Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 3.5.2
Security Advisory

WordPress 3.5.2: 31 Critical Security Vulnerabilities Explained

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
56 websites still running wordpress 3.5.2  → View full list
31
Total
3
Critical
7
High
21
Medium

WordPress 3.5.2 is an outdated version that contains 31 known security vulnerabilities, including 3 critical flaws that could allow attackers to take complete control of your website. While this version was released over a decade ago, security research shows that 56 websites are still running it—putting their data, visitor information, and business reputation at serious risk.

If your site is still powered by WordPress 3.5.2, you're likely exposed to multiple attack vectors including remote code execution, SQL injection, and cross-site scripting (XSS) attacks. These vulnerabilities can be exploited by cybercriminals to steal sensitive data, inject malware, deface your website, or use your server for illegal activities.

This comprehensive guide will help you understand what vulnerabilities exist in WordPress 3.5.2, how to check if you're affected, and most importantly, how to upgrade and secure your website immediately.

What is Wordpress 3.5.2?

WordPress 3.5.2 was released in 2013 as a maintenance update to the popular content management system. At that time, it was considered secure and included several bug fixes and improvements. However, like all software, WordPress evolves to address newly discovered security threats. WordPress 3.5.2 is now nearly 11 years old, and security researchers have identified numerous vulnerabilities that didn't exist when the version was released.

Think of WordPress 3.5.2 like an old lock on your front door. When it was installed, it provided adequate security for its time. But as thieves develop new lock-picking techniques, that old lock becomes increasingly vulnerable to break-ins. Modern WordPress versions are regularly updated with security patches to defend against new threats, while WordPress 3.5.2 receives no updates whatsoever, leaving it exposed to contemporary attack methods.

Key Vulnerabilities in Wordpress 3.5.2

31 CVEs found. The most critical are explained below.

CRITICAL CVE-2021-4434 10.0/10 · CVSS v3.1 ⏱ Immediate
Social Warfare Plugin - Attackers Can Run Code on Your Server

The Social Warfare plugin has a serious flaw that lets hackers run their own commands directly on your website's server. This happens through a feature called 'swp_url' that doesn't properly check what data it receives.

Impact: A hacker could take complete control of your website, steal customer data, install malware, or shut down your site entirely without needing to log in.

↗ View on NVD
CRITICAL CVE-2021-24507 9.8/10 · CVSS v3.1 ⏱ Immediate
Astra Pro Plugin - Database Can Be Attacked Without Login

The Astra Pro Addon plugin fails to properly filter user input before using it in database requests. Attackers can exploit this through pagination features that work for both visitors and logged-in users.

Impact: Hackers can access, modify, or delete your database contents, potentially exposing sensitive customer information or corrupting your website's data.

↗ View on NVD
CRITICAL CVE-2021-24649 9.8/10 · CVSS v3.1 ⏱ Immediate
WP User Frontend Plugin - Account Role Manipulation

The WP User Frontend plugin stores encrypted account permission levels in user registration forms. If an attacker obtains your site's encryption keys, they can decrypt and modify what permissions new accounts receive.

Impact: An attacker could create admin accounts for themselves, giving them full control over your website and all its data.

↗ View on NVD
HIGH CVE-2012-2399 10.0/10 · CVSS v2 ⏱ Within 7 days
File Upload Tool - Malicious Code Injection Vulnerability

An older file upload feature in WordPress (before version 3.5.2) doesn't properly validate text parameters, allowing attackers to inject malicious scripts. This flaw exists in the SWFupload tool used for media uploads.

Impact: Visitors to your site could be redirected to malicious pages, have their information stolen, or experience their browsers infected with malware.

↗ View on NVD
HIGH CVE-2021-25076 8.8/10 · CVSS v3.1 ⏱ Within 7 days
WP User Frontend Plugin - Subscriber List Can Be Attacked

The WP User Frontend plugin's subscriber dashboard doesn't properly filter the 'status' parameter before querying the database. This allows attackers to inject malicious code through the subscriber management area.

Impact: Hackers can access your subscriber database, modify records, display hidden information on your site, or compromise visitor browsers through injected scripts.

↗ View on NVD
HIGH CVE-2024-1893 8.8/10 · CVSS v3.1 ⏱ Within 30 days
Easy Property Listings Plugin - Database Query Vulnerability

The Easy Property Listings plugin doesn't properly secure the 'property_status' shortcode, allowing attackers to craft special queries that slowly extract information from your database without being detected immediately.

Impact: Attackers can slowly steal sensitive data from your database over time, including property information and potentially customer details.

↗ View on NVD

Additional Vulnerabilities (25 more)

Showing first 10 of 25. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2024-3240 HIGH 8.8 2024-05-04 The ConvertPlug plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.25 via deserialization of untrusted input from the 'settings_e…
CVE-2024-13655 HIGH 8.1 2025-03-07 The Flex Mag - Responsive WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capabil…
CVE-2024-4838 HIGH 7.5 2024-05-16 The ConvertPlus plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.26 via deserialization of untrusted input from the 'settings_e…
CVE-2025-30608 HIGH 7.1 2025-03-24 Cross-Site Request Forgery (CSRF) vulnerability in Anthony WordPress SQL Backup wordpress-sql-backup allows Stored XSS.This issue affects WordPress SQL Backup: from n/a through <=…
CVE-2024-3988 MEDIUM 6.4 2024-04-25 The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stor…
CVE-2024-7136 MEDIUM 6.4 2024-08-16 The JetSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 3.5.2 due to insufficient input saniti…
CVE-2025-4610 MEDIUM 6.4 2025-05-17 The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpmem_user_memberships shortcode in all versions up to, and inc…
CVE-2025-4479 MEDIUM 6.4 2025-06-19 The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin image comparison widget's before/after labels in al…
CVE-2025-6756 MEDIUM 6.4 2025-07-01 The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's UACF7_CUSTOM_FIELDS shortcode in all versions up to, and inc…
CVE-2025-3614 MEDIUM 6.4 2025-07-24 The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of a custom widget in all versions up to, an…
Full Report Available

All 31 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 3.5.2?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

Running WordPress 3.5.2 is like leaving your front door wide open for cybercriminals. With 3 critical vulnerabilities allowing remote code execution, plus SQL injection flaws and XSS attacks, your website is in serious danger. The good news is that upgrading is straightforward and takes less than an hour for most sites. Modern WordPress versions include automatic security updates, powerful built-in security features, and ongoing support from thousands of developers worldwide.

Don't wait for a security breach to force action. Use SiteRecipe.com to scan your website for vulnerabilities today, get a detailed report of any issues, and receive personalized recommendations for securing your site. Our expert security team can guide you through every step of the upgrade process and help you implement best practices to keep your WordPress site safe. Visit SiteRecipe.com now and take the first step toward a more secure website.

Frequently Asked Questions

Is WordPress 3.5.2 still supported with security updates?
No, WordPress 3.5.2 is no longer supported by the WordPress team. Security updates are only provided for the current version and the two previous major releases. Running an unsupported version means you won't receive patches for newly discovered vulnerabilities, leaving your site permanently at risk.
Can I use plugins to fix the vulnerabilities in WordPress 3.5.2?
No security plugin can fix the core vulnerabilities in WordPress 3.5.2. Most modern security plugins require newer WordPress versions to function properly. The only real solution is to upgrade to a current WordPress version, ideally the latest stable release available.
What happens if my website gets hacked through these vulnerabilities?
Hackers could steal customer data, inject malware into your site, redirect visitors to malicious sites, send spam emails from your server, or hold your data for ransom. Recovery can cost thousands of dollars and damage your business reputation permanently. Prevention through upgrading is far easier than dealing with a breach.
Will upgrading WordPress break my website?
Most upgrades go smoothly, especially with proper backups in place. However, old plugins and themes may not be compatible with newer WordPress versions. This is why testing on a backup copy first is important. SiteRecipe.com can help you identify compatibility issues before upgrading.
How often does WordPress release security updates?
WordPress releases security updates regularly—sometimes multiple times per month—whenever vulnerabilities are discovered. By keeping your site updated to the latest version, you automatically receive these patches and stay protected against new threats.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com