Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 4.2.21
Security Advisory

WordPress 4.2.21 Security: 2 Critical CVEs Explained

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
8 websites still running wordpress 4.2.21  → View full list
2
Total
2
Medium

WordPress 4.2.21 contains two medium-severity vulnerabilities that could expose your website to security risks. While no critical vulnerabilities have been identified in this version, the two medium-level CVEs discovered require immediate attention from site administrators. Understanding these threats and implementing proper fixes is essential to protecting your site from potential attacks.

This guide breaks down both CVEs affecting WordPress 4.2.21 in simple terms, explains what risks they pose to your website, and provides step-by-step instructions to secure your installation. Whether you're running a small blog or managing multiple WordPress sites, staying informed about these vulnerabilities is crucial for your online security.

What is Wordpress 4.2.21?

WordPress 4.2.21 is an older version of the popular WordPress content management system. Released years ago, this version powers approximately 8 known websites globally. While WordPress regularly releases updates with new features and security patches, version 4.2.21 has fallen behind the latest releases. Running older WordPress versions means you're missing out on critical security improvements and modern functionality that newer versions provide.

This particular version remains in use primarily on legacy websites or by site owners who haven't upgraded their installations. However, continuing to use outdated WordPress versions exposes your website to known security vulnerabilities that hackers actively exploit. The two medium-severity vulnerabilities found in 4.2.21 are examples of why staying current with WordPress updates is so important for protecting your site's integrity and user data.

Key Vulnerabilities in Wordpress 4.2.21

2 CVEs found. The most critical are explained below.

MEDIUM CVE-2025-14865 6.4/10 · CVSS v3.1 ⏱ Immediate
Passster Plugin Security Flaw Allows Malicious Code Injection

The Passster password protection plugin has a vulnerability that lets users with contributor-level access or higher inject harmful code into your website. This code runs in visitors' browsers when they view protected content, potentially compromising their data or your site's reputation.

Impact: Attackers could steal visitor information, redirect users to malicious sites, or inject ads and unwanted content into your password-protected pages. Your website's trustworthiness could be severely damaged.

↗ View on NVD
MEDIUM CVE-2021-36847 4.8/10 · CVSS v3.1 ⏱ Within 7 days
Webba Booking Plugin Admin Security Vulnerability

The Webba Booking plugin allows administrators to unintentionally inject harmful code that executes on your website. While this requires admin access, it's a risk if your admin account is compromised or if you have untrustworthy admin users.

Impact: An attacker with admin credentials could inject malicious code affecting all your website visitors, steal data, or take control of site functionality. This could lead to customer data theft or complete site compromise.

↗ View on NVD

Is your website running Wordpress 4.2.21?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

Securing WordPress 4.2.21 requires immediate action to patch the two medium-severity vulnerabilities discovered in this version. The CVE-2025-14865 and CVE-2021-36847 vulnerabilities could allow attackers to inject malicious scripts into your website, compromising user data and site integrity. Following our step-by-step fix guide will significantly reduce your security risk and protect your website from exploitation.

Don't leave your WordPress installation vulnerable another day. Visit SiteRecipe.com today to scan your entire website for security vulnerabilities, outdated software, and potential threats. Our comprehensive security analysis provides detailed reports and actionable recommendations to keep your WordPress site safe, secure, and compliant with the latest web standards. Protect your digital assets now with SiteRecipe.com's professional security tools.

Frequently Asked Questions

What exactly is CVE-2025-14865?
CVE-2025-14865 is a stored XSS vulnerability in the Passster password protection plugin affecting versions up to 4.2.24. Authenticated users can inject malicious scripts through the 'content_protector' shortcode, which can then execute in other users' browsers. This allows attackers to steal sensitive information or perform unauthorized actions on your site.
Am I affected if I don't use these specific plugins?
If you're running WordPress 4.2.21 but not using the Passster or Webba Booking plugins, you're not directly affected by these two CVEs. However, running an outdated WordPress version still leaves your site vulnerable to other known exploits. We strongly recommend updating to the latest WordPress version regardless.
How long does it take to update WordPress to a newer version?
Most WordPress updates take 5-15 minutes depending on your site size and plugin compatibility. We recommend updating during off-peak hours and maintaining a backup first. Using SiteRecipe.com's backup tools ensures you can restore your site if any compatibility issues arise during the update process.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com