Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 3.6.1
Security Advisory

WordPress 3.6.1: 35 Critical Vulnerabilities Explained

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
67 websites still running wordpress 3.6.1  → View full list
35
Total
3
Critical
6
High
24
Medium
2
Low

WordPress 3.6.1, released over a decade ago, is still running on approximately 67 websites worldwide. However, security researchers have identified a staggering 35 vulnerabilities in this version, including 3 critical-level flaws that pose immediate threats to site security. These vulnerabilities range from SQL injection attacks to unauthorized file deletion, making this outdated version a prime target for cybercriminals.

If your website is still using WordPress 3.6.1, you're operating with significantly outdated security protections. Modern attackers actively exploit known vulnerabilities in older versions, and leaving your site unpatched is like leaving your front door unlocked. This guide will help you understand the risks, identify if you're vulnerable, and take immediate action to protect your website and user data.

What is Wordpress 3.6.1?

WordPress 3.6.1 is an ancient version of the WordPress content management system, originally released in 2013. At that time, it was considered secure and feature-rich for managing websites and blogs. However, over the past decade, security researchers have continuously discovered new vulnerabilities in this version that were previously unknown. These flaws have never been patched because WordPress 3.6.1 is no longer supported by the development team.

Think of WordPress 3.6.1 like an old car model from 2013—it might still run, but it lacks modern safety features and security systems that newer models have. Hackers know exactly which vulnerabilities exist in this version and actively target websites still using it. Running WordPress 3.6.1 in 2024 is extremely dangerous and puts your entire website at risk of being compromised, hacked, or used to spread malware.

Key Vulnerabilities in Wordpress 3.6.1

35 CVEs found. The most critical are explained below.

CRITICAL CVE-2022-0867 9.8/10 · CVSS v3.1 ⏱ Immediate
Pricing Table Plugin - Unprotected Database Queries

The Pricing Table plugin has a security hole that lets attackers send malicious data directly to your website's database without logging in. This happens because the plugin doesn't properly check or clean the information before using it in database commands.

Impact: Attackers could steal sensitive data from your website, modify pricing information, or corrupt your database without needing a password.

↗ View on NVD
CRITICAL CVE-2024-13786 9.8/10 · CVSS v3.1 ⏱ Immediate
Education Theme - Malicious Code Injection Vulnerability

The education theme can be tricked into running dangerous code because it doesn't properly validate information it receives. An attacker can craft special data that, when processed, allows them to execute harmful commands on your site.

Impact: Hackers could gain control of your website, install malware, steal data, or use your site to attack other websites.

↗ View on NVD
CRITICAL CVE-2022-44584 9.1/10 · CVSS v3.1 ⏱ Immediate
WatchTowerHQ Plugin - Unauthorized File Deletion

The WatchTowerHQ plugin allows attackers to delete any files from your website without logging in. The plugin doesn't verify that the person requesting the deletion actually has permission to do so.

Impact: Your website could be partially or completely destroyed by deleting critical files needed to run WordPress.

↗ View on NVD
HIGH CVE-2013-4338 7.5/10 · CVSS v2 ⏱ Immediate
WordPress Core - Unsafe Data Processing Flaw

WordPress has a flaw in how it processes saved data. An attacker can exploit this to run unauthorized code by sending specially crafted information that tricks WordPress into executing malicious commands.

Impact: Your entire website could be compromised, allowing attackers to steal information, modify content, or take full control of your site.

↗ View on NVD
HIGH CVE-2013-4339 7.5/10 · CVSS v2 ⏱ Within 7 days
WordPress Core - Unsafe Redirect Vulnerability

WordPress doesn't properly check where it's sending users when they click certain links. An attacker can craft a link that appears legitimate but secretly redirects visitors to a malicious website.

Impact: Your visitors could be tricked into visiting phishing sites or malware pages, damaging your reputation and exposing them to attacks.

↗ View on NVD
HIGH CVE-2022-44583 7.5/10 · CVSS v3.1 ⏱ Immediate
WatchTowerHQ Plugin - Unauthorized File Download

The WatchTowerHQ plugin allows anyone to download files from your website without logging in. The plugin doesn't check permissions, so sensitive files can be accessed by anyone who knows how to ask for them.

Impact: Confidential information like customer data, financial records, or configuration files could be stolen and exposed publicly.

↗ View on NVD

Additional Vulnerabilities (29 more)

Showing first 10 of 29. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2024-12416 HIGH 7.5 2025-01-07 The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to SQL Injection via the 'woomotiv_seen_products_.*' cookie in all versions up to, and in…
CVE-2025-2011 HIGH 7.5 2025-05-06 The Slider & Popup Builder by Depicter plugin for WordPress is vulnerable to generic SQL Injection via the ‘s' parameter in all versions up to, and including, 3.6.1 due to insuffi…
CVE-2022-2903 HIGH 7.2 2022-09-26 The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (in…
CVE-2024-1761 MEDIUM 6.4 2024-03-07 The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget/block in all versions up to, and including, 3.6.1 due to insufficient inp…
CVE-2024-1957 MEDIUM 6.4 2024-04-13 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'give_form' shortcode in all versions up t…
CVE-2024-4452 MEDIUM 6.4 2024-05-21 The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in versions up to, and including, 3.6.1 due to insufficient input san…
CVE-2024-11198 MEDIUM 6.4 2024-11-19 The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘extra_class’ parameter in all versions up to, and including, 3.6.1 due to insuffici…
CVE-2025-12710 MEDIUM 6.4 2025-11-19 The Pet-Manager – Petfinder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the kwm-petfinder shortcode in all versions up to, and including, 3.6.1 due to in…
CVE-2026-3333 MEDIUM 6.4 2026-03-21 The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linkgate' shortcode in all versions up to, and including, 3.6.1 due t…
CVE-2020-29172 MEDIUM 6.1 2020-12-26 A cross-site scripting (XSS) vulnerability in the LiteSpeed Cache plugin before 3.6.1 for WordPress can be exploited via the Server IP setting.
Full Report Available

All 35 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 3.6.1?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 3.6.1 is no longer safe for any production website. With 35 known vulnerabilities—including 3 critical flaws that allow unauthorized access, file deletion, and code execution—staying on this version is an unacceptable security risk. The good news is that updating WordPress is straightforward and takes just minutes, yet provides exponential improvements to your site's security posture.

Don't let your website become another statistic in the cybercrime reports. Use SiteRecipe.com to scan your site for vulnerabilities, identify outdated software, and receive actionable recommendations for securing your WordPress installation. Our platform provides continuous monitoring and alerts, ensuring your site stays protected against emerging threats. Visit SiteRecipe.com today for a free security audit and take control of your website's safety.

Frequently Asked Questions

Can I get hacked just by running WordPress 3.6.1?
Yes, absolutely. Hackers actively scan for outdated WordPress versions and exploit known vulnerabilities. Running WordPress 3.6.1 makes your site an easy target, and compromise can happen within days or even hours of going live. The 3 critical vulnerabilities allow attackers to execute code, delete files, or access sensitive data without any authentication.
Will updating WordPress break my website?
Modern WordPress updates are designed to be backward compatible, though compatibility depends on your plugins and theme. Before updating, always back up your site. Most websites update without issues, but testing in a staging environment first is best practice for peace of mind and to catch any conflicts early.
Why is WordPress 3.6.1 still being used if it's so dangerous?
Many sites with WordPress 3.6.1 are abandoned or neglected by their owners. Some site owners don't realize their version is outdated or fear the update process. However, the security risk far outweighs any perceived benefits of staying on an old version that's no longer supported or receiving security patches.
What if I can't update because my hosting doesn't support newer versions?
This is a sign you need to change hosting providers. Modern hosting supports current WordPress versions and is often cheaper than legacy hosting. If your current host can't support WordPress 6.0+, they likely cut corners on security infrastructure as well, putting your site at additional risk beyond just the WordPress version.
How often should I check for vulnerabilities after updating?
You should monitor your site continuously for vulnerabilities. Use SiteRecipe.com to set up automated security scans that run weekly or monthly, alerting you immediately if new vulnerabilities are detected in your WordPress core, plugins, or themes. This proactive approach ensures you're never caught off-guard by emerging threats.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com