Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 4.0.1
Security Advisory

WordPress 4.0.1: 56 CVEs Found - Security Update Guide

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
30 websites still running wordpress 4.0.1  → View full list
56
Total
1
Critical
10
High
43
Medium
2
Low

WordPress 4.0.1 contains a significant security risk with 56 documented vulnerabilities, including 1 critical flaw and 10 high-severity issues that could compromise your website. Currently, approximately 30 websites are still running this vulnerable version, making them prime targets for cyberattacks. This comprehensive guide will help you identify if your site is affected and provide step-by-step instructions to secure your installation.

The most dangerous vulnerability is CVE-2023-3197, a critical unauthenticated SQL injection in the MStore API plugin that could allow attackers to access your entire database without any authentication. Additionally, multiple CSRF vulnerabilities and file upload exploits could grant attackers unauthorized access to your site's administrative functions and sensitive data.

What is Wordpress 4.0.1?

WordPress 4.0.1 is an older version of the world's most popular website platform, powering over 43% of all websites on the internet. It's designed to help anyone create and manage content without needing technical coding knowledge. However, this version was released over a decade ago and lacks the modern security protections that newer versions provide.

Think of WordPress like a house: older versions have outdated locks and security systems that hackers have learned how to bypass. WordPress 4.0.1 specifically has multiple doors (vulnerabilities) that attackers can use to break in, steal information, or take control of your website. While it may have worked fine when released, cybercriminals have since discovered 56 different ways to exploit it, making it extremely dangerous to run in 2024 or 2025.

Key Vulnerabilities in Wordpress 4.0.1

56 CVEs found. The most critical are explained below.

CRITICAL CVE-2023-3197 9.8/10 · CVSS v3.1 ⏱ Immediate
MStore API Plugin Database Hack

The MStore API plugin has a serious flaw that allows hackers to bypass login requirements and directly access your website's database. Attackers can extract sensitive information like customer data, passwords, and business information without needing any credentials.

Impact: Hackers could steal all your customer data, payment information, and confidential business records. Your website could be completely compromised and shut down.

↗ View on NVD
HIGH CVE-2021-34632 8.8/10 · CVSS v3.1 ⏱ Immediate
SEO Backlinks Plugin Malicious Script Injection

The SEO Backlinks plugin lacks proper security checks, allowing attackers to trick your users into running malicious code without their knowledge. This happens through a technique called 'Cross-Site Request Forgery' where hackers can force actions on behalf of your visitors.

Impact: Your users could be redirected to malicious websites, have their accounts compromised, or have malware installed on their computers.

↗ View on NVD
HIGH CVE-2024-7423 8.8/10 · CVSS v3.1 ⏱ Immediate
Stream Plugin Settings Can Be Changed Without Permission

The Stream plugin doesn't properly verify requests to change important website settings. Attackers can trick your site into making unwanted changes to critical configurations without your knowledge or authorization.

Impact: Hackers could alter your website settings, disable security features, create unauthorized admin accounts, or modify how your site functions.

↗ View on NVD
HIGH CVE-2025-2525 8.8/10 · CVSS v3.1 ⏱ Immediate
Streamit Theme Unsafe File Upload Vulnerability

The Streamit theme doesn't properly check what files users can upload to your server. This allows someone with even basic user access to upload dangerous files like viruses or backdoors.

Impact: Malicious files could be uploaded to take over your entire website, steal data, or use your server to attack other websites.

↗ View on NVD
HIGH CVE-2023-5504 8.7/10 · CVSS v3.1 ⏱ Within 7 days
BackWPup Plugin Backup Folder Security Flaw

The BackWPup backup plugin allows attackers to save backup files in unintended locations on your server. Combined with weak default settings, this could expose your complete website backups in accessible locations.

Impact: Your entire website including databases and files could be accessed, copied, or deleted by attackers.

↗ View on NVD
HIGH CVE-2026-9284 8.2/10 · CVSS v3.1 ⏱ Immediate
WooCommerce PayPal Orders Can Be Modified Without Permission

The WooCommerce PayPal Payments plugin doesn't properly verify that requests to create or view orders actually come from authorized users. Attackers can manipulate orders and access sensitive payment and customer information.

Impact: Hackers could create fake orders, change prices, access customer payment details, or bypass payment requirements entirely.

↗ View on NVD

Additional Vulnerabilities (50 more)

Showing first 10 of 50. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2024-13744 HIGH 8.1 2025-04-04 The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the validate_product_input_fields_on_add_to_cart fu…
CVE-2020-36716 HIGH 7.3 2023-06-07 The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the setup_page function in versions up to, and including, 4.0.1…
CVE-2024-13704 HIGH 7.2 2025-02-18 The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'st_user_title' parameter in all versions up to, and including, 4.0.1 due to insuf…
CVE-2024-13708 HIGH 7.2 2025-04-04 The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in versions 4.0.1 to 7.2.4 due to insufficient input sanitizatio…
CVE-2025-68887 HIGH 7.1 2026-01-08 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CMSJunkie - WordPress Business Directory Plugins WP-BusinessDirectory wp-busi…
CVE-2014-9037 MEDIUM 6.8 2014-11-25 WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an i…
CVE-2023-5505 MEDIUM 6.8 2024-08-17 The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the job-specific backup folder. This allows authenticated attack…
CVE-2024-34801 MEDIUM 6.5 2024-06-03 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mervin Praison Praison SEO WordPress seo-wordpress allows DOM-Based XSS.This …
CVE-2025-2519 MEDIUM 6.5 2025-04-08 The Sreamit theme for WordPress is vulnerable to arbitrary file downloads in all versions up to, and including, 4.0.1. This is due to insufficient file validation in the 'st_send_…
CVE-2025-13880 MEDIUM 6.5 2025-12-17 The WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and More) plugin for WordPress is vulnerable to unauthorized a…
Full Report Available

All 56 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 4.0.1?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 4.0.1 represents a critical security threat with 56 known vulnerabilities waiting to be exploited by attackers. The longer you delay updating, the higher your risk of data breach, malware infection, or complete loss of site control. By following this guide, you can secure your website and protect your visitors' data within the next few hours.

Don't leave your WordPress site vulnerable another day. Use SiteRecipe.com's website security scanning tool to continuously monitor your WordPress installation for vulnerabilities, receive instant alerts about new threats, and get automated recommendations for patches and updates. Our platform specifically tracks WordPress CVEs and plugin vulnerabilities so you'll never be caught running dangerous versions again. Start your free security scan today at SiteRecipe.com.

Frequently Asked Questions

Is WordPress 4.0.1 still receiving security updates?
No, WordPress 4.0.1 reached end-of-life years ago and no longer receives any security patches or updates. WordPress only supports the three most recent major versions. You must upgrade to at least version 6.0 or higher to receive ongoing security support and patches.
Will updating to the latest WordPress break my website?
While major updates can occasionally cause compatibility issues with very old plugins or themes, the risks of NOT updating are far greater. Always back up your site first, then test updates on a staging environment if possible. Most modern websites update without problems, and your hosting provider can help if issues occur.
What happens if my site gets hacked through WordPress 4.0.1?
Attackers could steal customer data, inject malware that infects visitors, send spam from your server, deface your website, or hold it for ransom. Recovery can cost thousands of dollars and damage your reputation. Prevention through timely updates is far cheaper and easier than dealing with a breach aftermath.
Can I stay on WordPress 4.0.1 if I disable the vulnerable plugins?
No, the WordPress core itself contains vulnerabilities independent of plugins. Even with all plugins disabled, your site remains at risk from core exploitation. You must upgrade the WordPress version itself to close these critical security holes.
How long does a WordPress update typically take?
Most WordPress updates complete in 1-5 minutes depending on your site's size and hosting performance. We recommend updating during off-peak hours, keeping your backup nearby, and testing key functionality afterward to ensure everything works correctly.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com