Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 4.5.2
Security Advisory

WordPress 4.5.2 Security: 19 CVEs Explained & Fixes

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
62 websites still running wordpress 4.5.2  → View full list
19
Total
2
High
15
Medium
2
Low

WordPress 4.5.2 is an outdated version that contains 19 known security vulnerabilities, including 2 high-severity issues that could compromise your website. If your site still runs this version, you're exposed to serious risks including unauthorized file uploads, script injection, and arbitrary file deletion attacks. This guide will help you identify if you're affected and show you exactly how to fix the problem.

With over 62 websites still using WordPress 4.5.2, this version represents a significant security risk in the wild. The vulnerabilities range from cross-site scripting (XSS) attacks to authenticated file manipulation that could lead to complete site takeover. Understanding these threats is the first step toward protecting your online presence.

What is Wordpress 4.5.2?

WordPress 4.5.2 is an older version of WordPress, the popular website building platform that powers over 40% of the internet. Released in May 2016, this version was once state-of-the-art but is now several major versions behind the current releases. Think of WordPress versions like software updates on your phone—older versions miss out on important security patches and performance improvements that newer versions include.

WordPress versions are numbered like 4.5.2, where each number represents different levels of updates. The first number (4) represents major releases, the second (5) represents minor updates, and the third (2) represents security patches. WordPress 4.5.2 may seem like it has patches, but it's missing years of additional security improvements from versions 5.x, 6.x, and beyond. Running outdated software is like leaving your front door unlocked—hackers specifically target known vulnerabilities in old versions.

Key Vulnerabilities in Wordpress 4.5.2

19 CVEs found. The most critical are explained below.

HIGH CVE-2020-11026 8.7/10 · CVSS v3.1 ⏱ Immediate
Malicious File Upload Can Run Code on Your Site

An attacker with login access can upload a specially named file that executes harmful code when someone views it. This is like giving a trusted employee a document that secretly contains a virus.

Impact: Hackers could take control of your website, steal data, or use your site to attack your visitors.

↗ View on NVD
HIGH CVE-2026-7252 8.1/10 · CVSS v3.1 ⏱ Immediate
WP-Optimize Plugin Can Delete Important Files

The WP-Optimize plugin (versions up to 4.5.2) has a flaw that lets attackers delete files from your server without permission. It's like someone being able to erase files from your filing cabinet remotely.

Impact: Your website could be damaged, lose functionality, or have critical data deleted permanently.

↗ View on NVD
MEDIUM CVE-2020-4047 6.8/10 · CVSS v3.1 ⏱ Within 7 days
Authors Can Inject Malicious Code Into Media

Staff members with permission to upload files can secretly embed malicious code that runs when an administrator views the file. The code runs with the admin's permissions, giving attackers powerful access.

Impact: An insider threat or compromised staff account could give attackers administrative control over your entire website.

↗ View on NVD
MEDIUM CVE-2020-11030 6.4/10 · CVSS v3.1 ⏱ Within 7 days
Block Editor Search Can Execute Harmful Scripts

Content creators using WordPress's block editor can craft special text in the search function that runs malicious code. This requires someone with editor access to intentionally create the harmful content.

Impact: A compromised staff account or malicious employee could inject code that affects all site visitors.

↗ View on NVD
MEDIUM CVE-2016-4566 6.1/10 · CVSS v3.0 ⏱ Within 30 days
Outdated File Upload Tool Allows Code Injection

WordPress 4.5.2 uses an old file upload component (Plupload) that has a security hole. Attackers can inject malicious code through the upload feature without needing to log in.

Impact: Your website could be hacked and used to spread malware to your visitors.

↗ View on NVD
MEDIUM CVE-2016-4567 6.1/10 · CVSS v3.0 ⏱ Within 30 days
Outdated Media Player Component Allows Code Injection

WordPress 4.5.2 uses an outdated media player that has a security flaw allowing attackers to inject malicious code into video or audio players.

Impact: Visitors watching videos could be infected with malware or have their browsers compromised.

↗ View on NVD

Additional Vulnerabilities (13 more)

Showing first 10 of 13. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2020-11027 MEDIUM 6.1 2020-04-30 In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user…
CVE-2022-1170 MEDIUM 6.1 2022-04-04 In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search form is provided through unsanitized GET requests.
CVE-2020-11025 MEDIUM 5.8 2020-04-30 In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires …
CVE-2020-11028 MEDIUM 5.8 2020-04-30 In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. This has been pat…
CVE-2020-11029 MEDIUM 5.8 2020-04-30 In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scripting (XSS) attacks. This has been…
CVE-2020-4048 MEDIUM 5.7 2020-06-12 In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect wh…
CVE-2020-4046 MEDIUM 5.4 2020-06-12 In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfiltered HTML in the block editor…
CVE-2022-2834 MEDIUM 5.3 2022-10-17 The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them…
CVE-2022-1995 MEDIUM 4.8 2022-06-27 The Malware Scanner WordPress plugin before 4.5.2 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Ja…
CVE-2022-2080 MEDIUM 4.3 2022-08-29 The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher or the original sender, allowing any authenticated user to …
Full Report Available

All 19 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 4.5.2?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 4.5.2 contains serious security vulnerabilities that put your website, visitor data, and business at risk. The two high-severity CVEs alone can allow attackers to execute malicious code on your site through file uploads and script injection. Updating to the latest WordPress version takes just minutes but provides years of security improvements and protections.

Don't wait for a breach to happen—take action today to secure your website. SiteRecipe.com's vulnerability scanner instantly identifies outdated software, missing security patches, and other critical issues affecting your site. Use our free security check to see exactly what vulnerabilities exist on your WordPress site, get personalized recommendations, and take the guesswork out of website security. Visit SiteRecipe.com now to scan your site and protect your business.

Frequently Asked Questions

Is WordPress 4.5.2 still supported with security updates?
No, WordPress 4.5.2 is no longer supported. WordPress only provides security updates for the latest version and sometimes the previous major version. Running unsupported versions means you won't receive security patches when new vulnerabilities are discovered, leaving your site permanently exposed to attacks.
Can I get hacked if I don't update from WordPress 4.5.2?
Yes, there's a significant risk. Hackers actively scan the internet for websites running vulnerable versions like 4.5.2 and exploit known CVEs to gain access. The longer you wait to update, the higher the chance of unauthorized access, data theft, or malware infection.
Will updating WordPress break my website?
Major updates occasionally cause issues with incompatible plugins or themes, but this is rare. The risk of a broken site from not updating is far higher than the small chance of update-related problems. Always backup before updating, and most sites update without any issues.
What's the difference between CVE-2020-11026 and the other vulnerabilities?
CVE-2020-11026 is rated 'HIGH' because it allows authenticated users to upload specially crafted files that execute malicious scripts. This is particularly dangerous if you have authors, contributors, or other users with upload permissions who could be compromised or malicious.
How long does it take to update from WordPress 4.5.2 to the latest version?
The actual update process typically takes 2-5 minutes. However, you should allow 15-30 minutes total to include creating a backup, running the update, and testing your site to ensure everything works correctly.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com