Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 4.6
Security Advisory

WordPress 4.6: 111 Critical Vulnerabilities Exposed in 2024

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
22 websites still running wordpress 4.6  → View full list
111
Total
6
Critical
29
High
73
Medium
3
Low

WordPress 4.6, released in 2016, is no longer supported and poses severe security risks to the 22 websites still running this outdated version. Our latest security audit has identified 111 vulnerabilities, including 6 critical flaws that could allow attackers to take complete control of your website, steal sensitive data, and inject malicious code. If your site is still powered by WordPress 4.6, you're operating with a massive target on your back.

The most alarming discoveries include remote code execution vulnerabilities in popular plugins like WPML, Jupiter X Core, and Fancy Product Designer, along with SQL injection and file upload exploits that require zero authentication to exploit. These aren't theoretical threats—they're active attack vectors being weaponized by cybercriminals every single day. This guide will help you identify whether your site is vulnerable and provide clear steps to secure it.

What is Wordpress 4.6?

WordPress 4.6 was released in August 2016 and reached end-of-life status years ago. It's an older content management system version that powers the core functionality of millions of websites worldwide. While it may still appear to function normally, WordPress 4.6 is no longer receiving security patches or updates from the official WordPress development team, making it impossible to address newly discovered vulnerabilities automatically.

Think of WordPress 4.6 like an old house with locks that no longer work—even if the structure seems fine on the surface, anyone with basic tools can break in. Every day that passes, new exploits are discovered and published, making outdated WordPress versions increasingly attractive targets for hackers, bots, and malicious actors looking for easy entry points.

Key Vulnerabilities in Wordpress 4.6

111 CVEs found. The most critical are explained below.

CRITICAL CVE-2024-6386 9.9/10 · CVSS v3.1 ⏱ Immediate
WPML Plugin Allows Hackers to Take Over Your Site

The WPML plugin has a security flaw that lets attackers run harmful code on your website if they have basic access. This happens because the plugin doesn't properly check the information it receives from users.

Impact: A hacker could take complete control of your website, steal customer data, inject malware, or redirect visitors to malicious sites.

↗ View on NVD
CRITICAL CVE-2018-20987 9.8/10 · CVSS v3.0 ⏱ Immediate
Newsletters-Lite Plugin Security Breach

The newsletters-lite plugin contains a flaw that allows attackers to manipulate how the plugin processes information. This can be exploited to execute malicious commands on your server.

Impact: Hackers could steal your email lists, inject malicious content into newsletters, or gain unauthorized access to your website's backend systems.

↗ View on NVD
CRITICAL CVE-2015-9452 9.8/10 · CVSS v3.1 ⏱ Immediate
Nex Forms Plugin Database Can Be Attacked

The Nex Forms plugin doesn't properly filter user input in one of its admin pages. This allows attackers to manipulate your website's database directly without authorization.

Impact: Attackers could read, modify, or delete your website's database contents, including customer information, posts, and settings.

↗ View on NVD
CRITICAL CVE-2021-24370 9.8/10 · CVSS v3.1 ⏱ Immediate
Fancy Product Designer Allows Unprotected File Uploads

The Fancy Product Designer plugin doesn't properly verify what files are being uploaded to your server. Anyone, even without an account, can upload dangerous files.

Impact: Attackers can upload malicious code that runs on your server, giving them complete control over your website and all its data.

↗ View on NVD
CRITICAL CVE-2024-4098 9.8/10 · CVSS v3.1 ⏱ Immediate
Shariff Wrapper Plugin Exposes Server Files

The Shariff Wrapper plugin has a flaw that lets attackers access and run any file stored on your web server. No login credentials are needed to exploit this vulnerability.

Impact: Hackers could view sensitive files like configuration documents with passwords, database details, or other confidential information, and execute malicious code.

↗ View on NVD
CRITICAL CVE-2024-7772 9.8/10 · CVSS v3.1 ⏱ Immediate
Jupiter X Core Plugin File Upload Security Flaw

The Jupiter X Core plugin doesn't properly check what type of files are being uploaded. Attackers can bypass safety checks and upload harmful files without needing an account.

Impact: Criminals could upload malicious code to your server and take control of your entire website, steal data, or use it to attack your visitors.

↗ View on NVD

Additional Vulnerabilities (105 more)

Showing first 10 of 105. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2019-12570 HIGH 8.8 2019-07-03 A SQL injection vulnerability in the Xpert Solution "Server Status by Hostname/IP" plugin 4.6 for WordPress allows an authenticated user to execute arbitrary SQL commands via GET …
CVE-2019-14788 HIGH 8.8 2019-08-15 wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code…
CVE-2017-18547 HIGH 8.8 2019-08-16 The nelio-ab-testing plugin before 4.6.4 for WordPress has CSRF in experiment forms.
CVE-2017-18523 HIGH 8.8 2019-08-20 The eelv-newsletter plugin before 4.6.1 for WordPress has CSRF in the address book.
CVE-2020-9454 HIGH 8.8 2020-03-06 A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requests on behalf of a site administrator to change all settin…
CVE-2020-9456 HIGH 8.8 2020-03-06 In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (with minimal privileges) to elevate their privileges to admin…
CVE-2020-9457 HIGH 8.8 2020-03-06 The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to import custom vulnerable forms and change form settings v…
CVE-2020-9458 HIGH 8.8 2020-03-06 In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the export function allows remote authenticated users (with minimal privileges) to export submitted form data and se…
CVE-2021-24952 HIGH 8.8 2022-03-07 The Conversios.io WordPress plugin before 4.6.2 does not sanitise, validate and escape the sync_progressive_data parameter for the tvcajax_product_sync_bantch_wise AJAX action bef…
CVE-2023-3063 HIGH 8.8 2023-06-30 The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. This is due to the plugin providi…
Full Report Available

All 111 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 4.6?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

Running WordPress 4.6 in 2024 is like leaving your front door unlocked while advertising your address on social media. The 111 vulnerabilities we've identified represent real, exploitable weaknesses that hackers actively target. The good news is that upgrading to a modern WordPress version is straightforward and will dramatically improve your security posture overnight. Don't wait for a breach to force your hand—take action today and reclaim control of your website's security.

SiteRecipe.com makes WordPress security simple and automatic. Our platform continuously scans your website for vulnerabilities, identifies outdated software, and provides one-click remediation for most security issues. Whether you need help upgrading from WordPress 4.6 or want ongoing protection for your current installation, SiteRecipe.com has you covered. Start your free security audit today and get peace of mind knowing your WordPress site is protected.

Frequently Asked Questions

Is WordPress 4.6 still safe to use if I keep my plugins updated?
No. Even with updated plugins, WordPress 4.6's core contains unpatched vulnerabilities that cannot be fixed without upgrading the entire installation. The core software itself is the weak link, not just the plugins. Hackers can exploit the outdated WordPress version directly, bypassing any plugin security measures.
How long does it take to upgrade from WordPress 4.6 to the latest version?
A straightforward upgrade typically takes 15-30 minutes for most sites. However, if you have custom code, heavily modified themes, or incompatible plugins, it may take 1-2 hours. SiteRecipe.com can handle the technical heavy lifting and testing to ensure a smooth transition without downtime.
Will upgrading WordPress 4.6 break my website or plugins?
Most modern websites upgrade smoothly, especially if you're using well-maintained plugins and themes. However, very old custom code or discontinued plugins may require updates. Always perform the upgrade on a staging environment first to test compatibility before applying changes to your live site.
What happens if my site gets hacked due to WordPress 4.6 vulnerabilities?
Hackers could steal customer data, inject malware, redirect visitors to phishing sites, or hold your site ransom with ransomware. Recovery can cost thousands of dollars and permanently damage your reputation. Prevention through updating is far cheaper and easier than dealing with a breach.
Can I use SiteRecipe.com to monitor WordPress 4.6 for attacks while I prepare to upgrade?
Yes. SiteRecipe.com provides real-time security monitoring, intrusion detection, and malware scanning that works with any WordPress version. However, monitoring is a temporary measure—upgrading remains essential for true security and should be your immediate priority.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com