Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 4.7.3
Security Advisory

WordPress 4.7.3 Security: 12 CVEs Explained & How to Fix

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
121 websites still running wordpress 4.7.3  → View full list
12
Total
1
High
10
Medium
1
Low

WordPress 4.7.3 is an older version of the popular website builder that contains 12 known security vulnerabilities. While some are minor, one critical flaw could expose your website to hackers who steal data, inject malware, or take your site offline. If you're running this version, you're putting your business at risk. This guide explains what went wrong, how to check if you're vulnerable, and the exact steps to protect your website.

What is Wordpress 4.7.3?

WordPress 4.7.3 was released in 2017 as a maintenance update to WordPress 4.7. It's the software that powers over 43% of all websites on the internet, making it a top target for cybercriminals. This version includes basic blogging tools, content management features, and the ability to add extensions called plugins and themes. Over 121 websites are still using this outdated version today, leaving themselves exposed to security threats.

Key Vulnerabilities in Wordpress 4.7.3

12 CVEs found. The most critical are explained below.

HIGH CVE-2024-13906 7.2/10 · CVSS v3.1 ⏱ Immediate
Gallery Plugin Code Injection Vulnerability

The Gallery by BestWebSoft plugin has a serious flaw that allows attackers to inject harmful code into your website through a file import feature. This happens because the plugin doesn't properly validate data before processing it, making it vulnerable to abuse by authenticated users.

Impact: An attacker could take control of your website, steal data, or inject malicious content that affects your visitors. This could lead to data breaches, loss of customer trust, and potential legal issues.

↗ View on NVD
MEDIUM CVE-2017-6819 6.5/10 · CVSS v3.0 ⏱ Within 7 days
Press This Feature Causes Server Overload

WordPress's Press This feature has a security flaw that allows attackers to trick it into downloading very large files from the internet. This can exhaust your server's resources and slow down or crash your website.

Impact: Your website could become slow or unavailable, resulting in lost sales and poor user experience. Your hosting provider may also charge additional fees for excessive resource usage.

↗ View on NVD
MEDIUM CVE-2025-3488 6.4/10 · CVSS v3.1 ⏱ Within 7 days
WPML Language Plugin Script Injection Risk

The WPML plugin's language switcher feature doesn't properly clean user input, allowing malicious code to be stored and executed on your website. This affects versions up to 4.7.3 and requires an attacker to have some level of access.

Impact: Visitors could be redirected to malicious sites, have their sessions hijacked, or see fake login forms designed to steal credentials. This damages your website's reputation and customer trust.

↗ View on NVD
MEDIUM CVE-2017-6815 6.1/10 · CVSS v3.0 ⏱ Within 30 days
Redirect URL Validation Can Be Bypassed

WordPress has a flaw in how it validates redirect URLs that allows attackers to use special characters to bypass security checks. This means users could be tricked into being redirected to malicious websites.

Impact: Visitors may be sent to phishing sites or malware downloads without realizing it. This can harm your users and reflect poorly on your website's trustworthiness.

↗ View on NVD
MEDIUM CVE-2017-6818 6.1/10 · CVSS v3.0 ⏱ Within 30 days
Category Names Can Contain Hidden Malicious Code

A flaw in WordPress allows malicious code to be hidden in category and tag names. When these names are displayed on your site, the hidden code executes in visitors' browsers.

Impact: Attackers could steal visitor information, inject advertisements, or redirect users to malicious sites. Your website could appear compromised and damage customer confidence.

↗ View on NVD
MEDIUM CVE-2025-58674 5.9/10 · CVSS v3.1 ⏱ Within 30 days
Author-Level Users Can Inject Malicious Code

WordPress has a vulnerability that allows users with Author permissions or higher to inject malicious scripts into your website content. This is a low-severity issue but still poses a risk depending on who has access.

Impact: If a disgruntled employee or compromised author account is abused, malicious code could be injected into pages affecting all your visitors. The damage depends on how many people have author-level access.

↗ View on NVD

Additional Vulnerabilities (6 more)

Showing first 10 of 6. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2017-6814 MEDIUM 5.4 2017-03-12 In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the…
CVE-2017-6817 MEDIUM 5.4 2017-03-12 In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds.
CVE-2024-6559 MEDIUM 5.3 2024-07-16 The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.7.3. Thi…
CVE-2017-6816 MEDIUM 4.9 2017-03-12 In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.
CVE-2025-58246 MEDIUM 4.3 2025-09-23 Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. The WordPress Core security team is aware of the issue and is…
CVE-2025-9218 LOW 3.7 2025-12-13 The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to to Information Disclosure due to missing authorization in the handle_rest_pre_dispatch() fu…
Full Report Available

All 12 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 4.7.3?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

Running WordPress 4.7.3 is like leaving your front door unlocked—hackers know exactly where to find the weaknesses. The 12 vulnerabilities discovered in this version, especially the PHP Object Injection and XSS flaws, give attackers multiple entry points to compromise your website. Upgrading takes less than 30 minutes and eliminates these known threats instantly. SiteRecipe.com offers free security scanning that identifies vulnerable WordPress versions on your site and alerts you to new CVEs before attackers exploit them. Visit SiteRecipe.com today to scan your website for free and get a detailed security report with step-by-step fix recommendations tailored to your specific setup.

Frequently Asked Questions

Is WordPress 4.7.3 still supported by the WordPress team?
No. WordPress 4.7.3 reached end-of-life in 2017 and no longer receives security updates. The WordPress security team has moved on to newer versions, meaning any new vulnerabilities discovered won't be patched. You must upgrade to a current version immediately.
What's the biggest risk with these 12 vulnerabilities?
The PHP Object Injection flaw (CVE-2024-13906) is the most dangerous—it allows hackers to run malicious code on your server without authentication. Combined with XSS vulnerabilities, attackers can steal customer data, inject malware, or completely take over your website.
Will upgrading to the latest WordPress break my website?
Most upgrades are smooth, especially if your plugins and themes are current. Backing up first ensures you can restore quickly if issues arise. After upgrading, test your site thoroughly to verify all features work. SiteRecipe.com can scan for compatibility issues before you upgrade.
How often should I update WordPress after upgrading from 4.7.3?
WordPress releases security updates every 1-2 weeks. Enable automatic updates in your settings so patches install immediately without manual work. SiteRecipe.com monitors all WordPress versions and alerts you instantly when new vulnerabilities are discovered.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com