Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 4.1.1
Security Advisory

WordPress 4.1.1: 43 CVEs Found - Critical Security Update

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
34 websites still running wordpress 4.1.1  → View full list
43
Total
2
Critical
10
High
30
Medium
1
Low

WordPress 4.1.1 is an older version of WordPress that contains 43 known security vulnerabilities, including 2 critical flaws that could allow attackers to take over your website. If your site is still running this outdated version, you're at serious risk of SQL injection attacks, unauthorized plugin installation, and remote code execution. This guide will help you identify if you're vulnerable and show you exactly how to fix it.

Security vulnerabilities in WordPress versions are documented in the CVE (Common Vulnerabilities and Exposures) database. The 43 flaws in WordPress 4.1.1 include dangerous issues affecting popular plugins like Popup Builder, Estatik Real Estate, and Coming Soon plugins. With 34 websites still using this vulnerable version, attackers are actively targeting this outdated software.

The good news is that upgrading to a newer WordPress version takes just minutes and will protect your site from nearly all of these threats. Let's walk through exactly how to check your version and apply the necessary security updates.

What is Wordpress 4.1.1?

WordPress 4.1.1 is an extremely outdated version of WordPress that was released years ago. WordPress is the software that powers over 43% of all websites on the internet—it's the platform you use to create and manage your website's content, design, and functionality. Think of it like the operating system for your website. Just like you update your phone or computer regularly, WordPress needs regular updates to stay secure and work properly.

Each version of WordPress is designed to fix bugs, add new features, and most importantly, patch security holes. WordPress 4.1.1 was released during an era when security threats were less advanced, so it lacks protections against modern attack methods. Running an outdated WordPress version is like leaving your front door unlocked—attackers know exactly how to break in because the vulnerabilities are publicly documented and easy to exploit.

Key Vulnerabilities in Wordpress 4.1.1

43 CVEs found. The most critical are explained below.

CRITICAL CVE-2022-0479 9.8/10 · CVSS v3.1 ⏱ Immediate
Popup Builder Plugin Data Theft and Website Defacement

A popular popup plugin has a security flaw that allows attackers to steal your subscriber database or inject malicious code into your website. Hackers can exploit this without needing to log in to your admin panel.

Impact: Your customer email list could be stolen, and attackers could deface your website or redirect visitors to malicious sites.

↗ View on NVD
CRITICAL CVE-2023-6049 9.8/10 · CVSS v3.1 ⏱ Immediate
Real Estate Plugin Cookie Vulnerability

The Estatik Real Estate plugin stores data in cookies that isn't properly validated. Attackers can manipulate these cookies to run malicious code on your website without needing an account.

Impact: Hackers could take control of your website, steal data, or inject malware that affects all your visitors.

↗ View on NVD
HIGH CVE-2024-10728 8.8/10 · CVSS v3.1 ⏱ Immediate
Unauthorized Plugin Installation Vulnerability

The PostX plugin allows attackers to install and activate unauthorized plugins on your website without permission. This bypasses normal security checks that require admin approval.

Impact: Malicious plugins could be secretly installed to steal data, display ads, or completely compromise your website.

↗ View on NVD
HIGH CVE-2024-13232 8.8/10 · CVSS v3.1 ⏱ Immediate
Import/Export Plugin Admin Privilege Bypass

The Import & Export plugin has a flaw allowing attackers to run database commands and gain administrative access without proper authorization. The plugin doesn't verify user permissions before allowing sensitive actions.

Impact: Attackers could access your entire database, modify content, create rogue admin accounts, or steal all your website data.

↗ View on NVD
HIGH CVE-2025-48101 8.8/10 · CVSS v3.1 ⏱ Immediate
Constant Contact Plugin Code Execution Flaw

The Constant Contact email marketing plugin improperly handles data, allowing attackers to inject malicious code that executes on your server. This is a technical vulnerability that doesn't require hacker skills to exploit.

Impact: Your website could be completely compromised, allowing hackers to steal customer data or turn your site into a spam distribution center.

↗ View on NVD
HIGH CVE-2026-6518 8.8/10 · CVSS v3.1 ⏱ Immediate
Coming Soon Plugin Allows Malware Upload

The CMP Coming Soon plugin accepts file uploads without proper security checks. Attackers can upload malicious files to run code directly on your server and take over your website.

Impact: Hackers could upload ransomware, steal all your files, or completely hijack your website for illegal activities.

↗ View on NVD

Additional Vulnerabilities (37 more)

Showing first 10 of 37. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2024-24796 HIGH 8.2 2024-02-12 Deserialization of Untrusted Data vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin.This issue affects Event…
CVE-2023-0812 HIGH 7.5 2023-05-15 The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthentic…
CVE-2023-5003 HIGH 7.5 2023-10-16 The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unf…
CVE-2024-8352 HIGH 7.5 2024-10-03 The Social Web Suite – Social Media Auto Post, Social Media Auto Publish plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.1.11 via…
CVE-2025-4206 HIGH 7.2 2025-05-09 The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file pa…
CVE-2025-32520 HIGH 7.1 2025-04-17 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M. Ali Saleem WordPress Health and Server Condition – Integrated with Google …
CVE-2016-11011 MEDIUM 6.5 2019-09-20 The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.
CVE-2023-6048 MEDIUM 6.5 2024-01-15 The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not prevent user with low privileges on the site, like subscribers, from setting any of the site's options to 1, …
CVE-2024-13341 MEDIUM 6.5 2025-02-01 The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to SQL Injection via the 'data-id' parameter in all versions up to, and includi…
CVE-2024-5223 MEDIUM 6.4 2024-05-30 The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file uploading feature in all v…
Full Report Available

All 43 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 4.1.1?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

Running WordPress 4.1.1 puts your website at critical risk. With 43 known vulnerabilities including 2 critical flaws, your site could be compromised through SQL injection attacks, unauthorized plugin installation, or remote code execution. The hackers exploiting these vulnerabilities are actively targeting outdated sites, and the process to fix it is surprisingly simple—most updates complete in under 5 minutes.

Don't wait until your site gets hacked. Use SiteRecipe.com to continuously monitor your WordPress version, plugins, and security status. Our platform automatically alerts you to vulnerabilities affecting your site and provides one-click guidance for fixing them. Protect your website today—sign up for SiteRecipe.com and get instant visibility into your security posture with detailed reports and actionable recommendations.

Frequently Asked Questions

Is WordPress 4.1.1 still supported by WordPress?
No, WordPress 4.1.1 reached end-of-life years ago and no longer receives security updates. WordPress only supports the current version and a few recent previous versions with security patches. Running 4.1.1 means you'll never receive fixes for newly discovered vulnerabilities.
Will updating WordPress break my plugins or theme?
Most modern plugins and themes are designed to work with current WordPress versions. However, if you're using very old plugins designed specifically for version 4.1.1, you may need to update or replace them. Always backup your site before updating to minimize risk.
What's the difference between Critical, High, and Medium vulnerabilities?
Critical vulnerabilities can lead to complete site takeover or data theft with minimal effort. High vulnerabilities require some user interaction or specific conditions but still pose serious risks. Medium vulnerabilities are less severe but should still be patched. All 43 vulnerabilities in WordPress 4.1.1 should be addressed by upgrading.
How often should I update WordPress?
You should apply WordPress security updates as soon as they're released—ideally within days. Major version updates should be done within a few weeks. Using SiteRecipe.com ensures you'll never miss a critical security update for your version.
Can I update WordPress myself, or do I need a developer?
WordPress updates are designed to be simple enough for anyone. You can do it yourself through your admin dashboard in minutes. However, if you're uncomfortable with technology, your hosting provider or a WordPress expert can handle it for you.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com