Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 4.1
Security Advisory

WordPress 4.1: 312 CVEs Found - Security Update Guide

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
28 websites still running wordpress 4.1  → View full list
312
Total
13
Critical
60
High
227
Medium
12
Low

WordPress 4.1 is an outdated version that poses significant security risks to your website. Our security analysis has identified 312 known vulnerabilities, including 13 critical-severity flaws that could allow attackers to gain complete control of your site. If you're still running WordPress 4.1, your website is likely exposed to active exploits being used by malicious actors right now.

This comprehensive guide will help you understand the risks, check if your site is vulnerable, and implement the necessary security updates. We've analyzed the most dangerous vulnerabilities affecting WordPress 4.1 and created step-by-step instructions to protect your business, customer data, and online reputation.

What is Wordpress 4.1?

WordPress 4.1 is an older version of the popular WordPress content management system released in February 2015. It was designed to help website owners easily create, manage, and publish content without technical knowledge. Millions of websites worldwide have relied on WordPress to power their online presence, from small blogs to major news outlets and e-commerce stores.

However, WordPress 4.1 reached end-of-life support years ago, meaning WordPress developers no longer provide security patches or updates for newly discovered vulnerabilities. This means any security flaw discovered after its release—and there are 312 of them—remains unpatched on your site. Running outdated software is like leaving your front door unlocked; attackers actively scan for websites using vulnerable versions and exploit them for profit.

Key Vulnerabilities in Wordpress 4.1

312 CVEs found. The most critical are explained below.

CRITICAL CVE-2019-13569 9.8/10 · CVSS v3.0 ⏱ Immediate
Email Subscribers Plugin Database Attack

The Icegram Email Subscribers plugin has a weakness that lets hackers send specially crafted requests to access your website's database directly. They can view, modify, or delete any information stored in your database without permission.

Impact: Attackers could steal customer emails, passwords, and personal information, or corrupt your entire database making your website non-functional.

↗ View on NVD
CRITICAL CVE-2020-10564 9.8/10 · CVSS v3.1 ⏱ Immediate
File Upload Plugin Remote Control Vulnerability

The File Upload plugin allows attackers to upload malicious files that can execute code on your server. This gives hackers complete control over your website as if they were sitting at your computer.

Impact: Hackers could take full control of your website, steal all data, inject malware for your visitors, or use your server to attack other websites.

↗ View on NVD
CRITICAL CVE-2021-24175 9.8/10 · CVSS v3.1 ⏱ Immediate
Elementor Plugin Admin Login Bypass

The Plus Addons for Elementor plugin has a critical flaw where anyone can log in as an administrator without knowing the password. Attackers only need a username to gain complete access.

Impact: Criminals could log in as your admin account, modify your website, steal data, add malware, or lock you out of your own website.

↗ View on NVD
CRITICAL CVE-2021-24951 9.8/10 · CVSS v3.1 ⏱ Immediate
LearnPress Plugin Database Injection Flaw

The LearnPress plugin has a database vulnerability similar to SQL injection where attackers can manipulate course duplication requests to access or modify your database. This happens because the plugin doesn't properly validate user inputs.

Impact: Hackers could steal course data, student information, grades, and payment details, or corrupt your learning platform entirely.

↗ View on NVD
CRITICAL CVE-2022-0479 9.8/10 · CVSS v3.1 ⏱ Immediate
Popup Builder Plugin Database and XSS Attack

The Popup Builder plugin fails to properly check popup subscription IDs, allowing hackers to inject harmful code into your database or steal information from your site visitors' browsers.

Impact: Attackers could steal visitor data, inject malware into your site, or launch attacks against your customers' computers through your website.

↗ View on NVD
CRITICAL CVE-2022-2317 9.8/10 · CVSS v3.1 ⏱ Within 7 days
Simple Membership Plugin Privilege Escalation

The Simple Membership plugin allows users to change their membership level during signup without proper verification. Users can upgrade to premium or admin status without paying or being authorized.

Impact: You could lose revenue from membership fees, and unauthorized users could gain access to premium content or administrative features they shouldn't have.

↗ View on NVD

Additional Vulnerabilities (306 more)

Showing first 10 of 306. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2023-3277 CRITICAL 9.8 2023-11-03 The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation o…
CVE-2023-6049 CRITICAL 9.8 2024-01-15 The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which could allow unauthenticated users to perform PHP Object Injecti…
CVE-2024-4413 CRITICAL 9.8 2024-05-14 The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.11.1 via deserialization of untrusted input. This makes i…
CVE-2024-6328 CRITICAL 9.8 2024-07-12 The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.14.7. This is du…
CVE-2024-13824 CRITICAL 9.8 2025-03-14 The CiyaShop - Multipurpose WooCommerce Theme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.19.0 via deserialization of untrust…
CVE-2022-47615 CRITICAL 9.3 2023-01-26 Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.
CVE-2024-8671 CRITICAL 9.1 2024-09-24 The WooEvents - Calendar and Event Booking plugin for WordPress is vulnerable to arbitrary file overwrite due to insufficient file path validation in the inc/barcode.php file in a…
CVE-2019-16120 HIGH 8.8 2019-09-08 CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature.
CVE-2017-18597 HIGH 8.8 2019-09-10 The jtrt-responsive-tables plugin before 4.1.2 for WordPress has SQL Injection via the admin/class-jtrt-responsive-tables-admin.php tableId parameter.
CVE-2021-24307 HIGH 8.8 2021-05-24 The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_settings" privilege (most of the ti…
Full Report Available

All 312 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 4.1?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 4.1 contains 13 critical vulnerabilities that are actively being exploited by cybercriminals. The most dangerous flaws include SQL injection attacks that give attackers direct database access, authentication bypass vulnerabilities that let them log in as administrators, and remote code execution exploits that provide complete site control. Waiting to update your site puts your business at extreme risk of data breaches, malware infections, and customer trust violations.

Don't leave your website's security to chance. Use SiteRecipe.com's advanced vulnerability scanner to detect all security issues on your site, prioritize critical fixes, and track your progress as you implement updates. Our platform provides detailed remediation guidance and continuous monitoring to ensure your WordPress installation stays secure long after the initial upgrade. Protect your business today—scan your site with SiteRecipe.com now.

Frequently Asked Questions

How serious is running WordPress 4.1 in 2024?
Extremely serious. WordPress 4.1 has 312 known vulnerabilities with 13 rated as critical severity. These flaws are publicly documented, meaning hackers have detailed instructions on how to exploit them. Websites running outdated software are compromised daily.
Can I upgrade WordPress without losing my content?
Yes, absolutely. WordPress upgrades are designed to preserve all your posts, pages, media, and settings. The key is to back up your site before upgrading. Most users experience seamless upgrades with zero data loss.
What should I do if my site is already hacked?
Contact your hosting provider or a WordPress security specialist immediately. Malware can spread quickly and compromise customer data. Use SiteRecipe.com's security audit to identify what was compromised, then restore from a clean backup and upgrade to the latest WordPress version.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com