Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 4.3.1
Security Advisory

WordPress 4.3.1: 27 CVEs Found - Critical Security Update

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
153 websites still running wordpress 4.3.1  → View full list
27
Total
3
Critical
6
High
18
Medium

WordPress 4.3.1 is an outdated version running on approximately 153 websites worldwide, and it contains a staggering 27 security vulnerabilities that put your site at serious risk. Among these are 3 critical flaws that could allow attackers to execute SQL injection attacks, compromise your database, and steal sensitive information. If you're still using WordPress 4.3.1, your website is vulnerable to exploitation by cybercriminals who actively scan for these known weaknesses.

This comprehensive guide will help you identify whether your site is running this vulnerable version and provide you with actionable steps to protect your WordPress installation. Whether you manage a small blog or a large business website, upgrading from WordPress 4.3.1 is one of the most important security decisions you can make today.

What is Wordpress 4.3.1?

WordPress 4.3.1 is an older version of the popular website building platform that was released several years ago. While it may have worked well when it was current, WordPress continuously releases security updates to patch newly discovered vulnerabilities. Version 4.3.1 has now reached end-of-life status, meaning it no longer receives security updates or support from the WordPress development team. Running outdated software is one of the most common reasons websites get hacked, as attackers specifically target known vulnerabilities in older versions.

Think of WordPress 4.3.1 like an old car without updated safety features—it might still run, but it's missing critical protections that modern versions have. The platform itself is excellent for building websites, but only when you keep it updated regularly. Every WordPress version includes patches for security holes discovered in previous releases, and by using 4.3.1, you're essentially leaving your digital door unlocked.

Key Vulnerabilities in Wordpress 4.3.1

27 CVEs found. The most critical are explained below.

CRITICAL CVE-2019-20361 9.8/10 · CVSS v3.1 ⏱ Immediate
Email Subscribers plugin - Hackers can steal your database

The Email Subscribers & Newsletters plugin has a security hole that lets attackers sneak harmful commands into your database. Think of it like someone finding a back door to your filing cabinet and being able to read or modify your files without permission.

Impact: Attackers could steal your subscriber lists, customer emails, passwords, and other sensitive information stored in your database. They could also modify or delete your data.

↗ View on NVD
CRITICAL CVE-2022-3463 9.8/10 · CVSS v3.1 ⏱ Within 7 days
Contact Form plugin - Malicious data in exported files

The Contact Form Plugin doesn't properly clean data when you export form responses as Excel files. An attacker could hide malicious instructions in form submissions that activate when you open the exported file.

Impact: When you download and open your form submissions, the file could execute harmful commands on your computer or infect it with malware.

↗ View on NVD
CRITICAL CVE-2023-28662 9.8/10 · CVSS v3.1 ⏱ Immediate
Gift Cards plugin - Unauthorized database access

The Gift Cards plugin has a critical vulnerability that lets anyone (without even logging in) inject malicious commands into your database through a hidden parameter. Attackers don't need special access—they can attack from outside your website.

Impact: Hackers can steal your gift card data, customer information, payment details, and any other information in your database. They could also modify or delete critical data.

↗ View on NVD
HIGH CVE-2016-10876 8.8/10 · CVSS v3.0 ⏱ Within 30 days
Database Backup plugin - Attackers trick you into bad actions

The Database Backup plugin is missing a security check that verifies requests are legitimate. An attacker could trick you into clicking a malicious link that performs unwanted actions on your site.

Impact: Attackers could force you to delete backups, change settings, or perform other dangerous actions without your knowledge or consent.

↗ View on NVD
HIGH CVE-2024-5034 8.8/10 · CVSS v3.1 ⏱ Within 7 days
SULly plugin - Attackers trick logged-in users into bad actions

The SULly plugin is missing security checks in certain areas, allowing attackers to trick logged-in users into performing unwanted actions. If you visit a malicious website while logged into your WordPress site, the attacker could make changes without your knowledge.

Impact: Attackers could modify user accounts, change settings, delete content, or take other unwanted actions on your site by exploiting your logged-in session.

↗ View on NVD
HIGH CVE-2026-5127 8.8/10 · CVSS v3.1 ⏱ Immediate
User Frontend plugin - Attackers can inject malicious code

The User Frontend plugin doesn't properly validate file uploads, allowing attackers to upload dangerous files that could run code on your server. This could happen through the file upload features in the plugin.

Impact: Attackers could take complete control of your website, steal all your data, install malware, or use your server to attack other websites.

↗ View on NVD

Additional Vulnerabilities (21 more)

Showing first 10 of 21. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2023-6696 HIGH 8.1 2024-06-15 The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capabil…
CVE-2024-13491 HIGH 7.5 2025-02-19 The Small Package Quotes – For Customers of FedEx plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, an…
CVE-2024-5151 HIGH 7.1 2024-07-13 The SULly WordPress plugin before 4.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Script…
CVE-2025-4577 MEDIUM 6.4 2025-06-10 The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-color attribute in all versio…
CVE-2025-14387 MEDIUM 6.4 2025-12-15 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.3.1 due to insufficient input sanit…
CVE-2015-5714 MEDIUM 6.1 2016-05-22 Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML el…
CVE-2016-10875 MEDIUM 6.1 2019-08-12 The wp-database-backup plugin before 4.3.1 for WordPress has XSS.
CVE-2022-1617 MEDIUM 6.1 2024-01-16 The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping in some of them, allowi…
CVE-2024-5033 MEDIUM 5.9 2024-07-13 The SULly WordPress plugin before 4.3.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in adm…
CVE-2015-7989 MEDIUM 5.4 2016-05-22 Cross-site scripting (XSS) vulnerability in the user list table in WordPress before 4.3.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted e-…
Full Report Available

All 27 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 4.3.1?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 4.3.1 poses an unacceptable security risk to your website and your visitors' data. With 3 critical vulnerabilities including SQL injection flaws that could expose your entire database, continuing to use this version is essentially inviting hackers to compromise your site. The good news is that upgrading to a current WordPress version is straightforward and takes just minutes, immediately eliminating these known threats and protecting your digital assets.

Don't wait for a breach to happen—take action today. Use SiteRecipe.com's free vulnerability scanner to identify all security issues on your WordPress site, get personalized upgrade recommendations, and access step-by-step guides to keep your website safe. Our platform helps thousands of website owners monitor their WordPress security, detect vulnerabilities before attackers find them, and maintain compliance with security best practices. Visit SiteRecipe.com now for a free security audit of your website.

Frequently Asked Questions

How serious are the vulnerabilities in WordPress 4.3.1?
Very serious. WordPress 4.3.1 contains 3 critical vulnerabilities including SQL injection flaws that allow attackers to directly access and manipulate your database without authentication. These are considered critical because they enable complete compromise of your website and can lead to data theft, malware installation, and site takeover. Updating immediately is essential.
Will upgrading from WordPress 4.3.1 break my website?
While upgrading does carry minimal risk, most websites transition smoothly from older WordPress versions to current ones. The key to a safe upgrade is backing up your site first, updating plugins and themes beforehand, and testing thoroughly afterward. SiteRecipe.com provides detailed upgrade guides customized to your specific setup to minimize any issues.
Can I skip versions and upgrade directly from 4.3.1 to the latest WordPress?
Yes, you can upgrade directly from WordPress 4.3.1 to the latest version. WordPress is designed to handle multi-version upgrades automatically, though it's still critical to back up your site first and ensure all plugins are compatible with the newer version before proceeding.
What happens if I don't upgrade from WordPress 4.3.1?
If you don't upgrade, your site remains vulnerable to active exploitation. Hackers regularly scan for WordPress 4.3.1 installations because they know about these specific CVEs. Your site could be compromised for malware distribution, ransomware, data theft, or used in attacks against others—often without your knowledge.
How can SiteRecipe.com help me stay secure?
SiteRecipe.com provides continuous vulnerability scanning, security monitoring, and personalized recommendations for your WordPress site. We identify outdated versions, detect CVEs specific to your setup, and provide step-by-step remediation guides so you can stay ahead of threats.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com