Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 4.8
Security Advisory

WordPress 4.8 Security: 99 Critical Vulnerabilities Explained

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
120 websites still running wordpress 4.8  → View full list
99
Total
10
Critical
18
High
67
Medium
4
Low

WordPress 4.8, released in 2017, is now severely outdated and poses significant security risks to your website. Our analysis reveals 99 documented vulnerabilities, including 10 critical flaws that could allow attackers to steal data, take over accounts, and delete files. If your site still runs this version, immediate action is required to protect your business.

We've identified that 120 websites are still using WordPress 4.8, making them prime targets for cybercriminals. The most dangerous vulnerabilities involve SQL injection attacks through popular plugins like WP Easy Gallery, ChatBot, and WP Foodbakery. These exploits can be executed remotely without authentication, giving hackers direct access to your database.

This comprehensive guide walks you through identifying if you're vulnerable, understanding the risks, and safely upgrading to a secure version. We'll also show you how SiteRecipe.com can streamline your security updates and protect your WordPress installation.

What is Wordpress 4.8?

WordPress 4.8 is a version of the world's most popular website builder, released in June 2017. At that time, it was cutting-edge software, but years of security updates have made it dangerously outdated. Think of it like driving a car from 2017 without any safety updates—it worked fine then, but modern highways and traffic require modern safety features.

WordPress powers over 43% of all websites worldwide, making it both popular and a frequent target for hackers. Version 4.8 was superseded by newer versions that patched critical security holes. Using an old WordPress version is like leaving your front door unlocked; attackers know exactly where to find vulnerabilities because they're well-documented and unpatched in older installations.

Key Vulnerabilities in Wordpress 4.8

99 CVEs found. The most critical are explained below.

CRITICAL CVE-2024-8436 9.9/10 · CVSS v3.1 ⏱ Immediate
WP Easy Gallery Plugin - Unauthorized Database Access

The WP Easy Gallery plugin has a security flaw that allows hackers to directly access your website's database through specially crafted requests. This happens because the plugin doesn't properly validate user inputs before using them in database queries. If you're using this plugin version 4.8.5 or earlier, your site is at risk.

Impact: Attackers could steal sensitive customer data, modify website content, create fake admin accounts, or completely compromise your website's database.

↗ View on NVD
CRITICAL CVE-2017-14723 9.8/10 · CVSS v3.0 ⏱ Immediate
WordPress Core Database Query Vulnerability

This is a flaw in WordPress itself (versions before 4.8.2) in how it processes certain database commands. Plugins and themes can accidentally create security holes that allow hackers to access your database. The issue involves how WordPress handles special characters in database requests.

Impact: Hackers could gain unauthorized access to your database, steal customer information, or take control of your website.

↗ View on NVD
CRITICAL CVE-2017-16510 9.8/10 · CVSS v3.0 ⏱ Immediate
WordPress Database Command Processing Flaw

WordPress versions before 4.8.3 have a flaw in how it processes database commands when they're prepared twice by mistake. This creates a security loophole that plugins or themes could accidentally exploit. It's a different problem than CVE-2017-14723 but equally serious.

Impact: Hackers could exploit plugins or themes using this flaw to access your database, steal data, or take control of your website.

↗ View on NVD
CRITICAL CVE-2023-5204 9.8/10 · CVSS v3.1 ⏱ Immediate
ChatBot Plugin - Unauthorized Database Access

The ChatBot plugin (version 4.8.9 and earlier) doesn't properly check user inputs before using them in database queries. Hackers don't even need to log in to exploit this—they can attack from outside your website.

Impact: Attackers could access your database, steal customer information, modify website data, or take over your website without any login credentials.

↗ View on NVD
CRITICAL CVE-2023-5991 9.8/10 · CVSS v3.1 ⏱ Immediate
Hotel Booking Plugin - File Access and Deletion Vulnerability

The Hotel Booking Lite plugin (versions before 4.8.5) doesn't properly protect files on your server. Attackers can request and download sensitive files or delete important website files without needing to log in. The plugin also lacks security checks to prevent these actions.

Impact: Hackers could download backup files, configuration files with passwords, or delete critical website files, causing your site to become unavailable or exposing sensitive data.

↗ View on NVD
CRITICAL CVE-2025-0181 9.8/10 · CVSS v3.1 ⏱ Immediate
WP Foodbakery Plugin - Account Takeover Vulnerability

The WP Foodbakery plugin (version 4.8 and earlier) fails to properly verify user identity when logging in. An attacker can bypass this verification and log in as any user, including administrators, without knowing their password.

Impact: Hackers could take over admin accounts, change your website, steal customer data, inject malicious code, or completely compromise your website.

↗ View on NVD

Additional Vulnerabilities (93 more)

Showing first 10 of 93. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2025-4689 CRITICAL 9.8 2025-07-02 The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion which leads to Remote Code Execution in all versions up…
CVE-2025-5397 CRITICAL 9.8 2025-10-31 The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.8.1. This is due to the check_login() function not properly v…
CVE-2023-5212 CRITICAL 9.6 2023-10-19 The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as well as version 4.9.2. This makes it possible for authentic…
CVE-2023-5241 CRITICAL 9.6 2023-10-19 The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. T…
CVE-2021-24750 HIGH 8.8 2021-12-21 The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenti…
CVE-2024-4662 HIGH 8.8 2024-05-23 The Oxygen Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.8.2 via post metadata. This is due to the plugin storing cus…
CVE-2024-3813 HIGH 8.8 2024-06-15 The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8 via the 'td_block_title' shortcode 'block_template_id' att…
CVE-2024-9018 HIGH 8.8 2024-10-01 The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘key’ parameter in all versions up to, and including, 4.8.5 d…
CVE-2024-9849 HIGH 8.8 2024-11-16 The Real3D Flipbook Lite – 3D FlipBook, PDF Viewer, PDF Embedder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'r3dfb_sav…
CVE-2025-0366 HIGH 8.8 2025-02-01 The Jupiter X Core plugin for WordPress is vulnerable to Local File Inclusion to Remote Code Execution in all versions up to, and including, 4.8.7 via the get_svg() function. This…
Full Report Available

All 99 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 4.8?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 4.8 carries unacceptable security risks in 2024. With 10 critical vulnerabilities that allow SQL injection, account takeover, and file deletion, your website, customer data, and business reputation are at serious risk. The good news is that upgrading is straightforward and takes just minutes. Modern WordPress versions receive security patches regularly, and the upgrade process has become much more user-friendly.

Don't wait for a breach to happen. Use SiteRecipe.com's WordPress security scanner today to identify vulnerabilities across your entire site, receive step-by-step upgrade guidance, and get automated security monitoring. Our platform makes WordPress security maintenance effortless, so you can focus on running your business while we protect it. Start your free security scan now and upgrade with confidence.

Frequently Asked Questions

What happens if I don't upgrade from WordPress 4.8?
Your site becomes increasingly vulnerable to automated attacks. Hackers actively exploit known WordPress 4.8 vulnerabilities to inject malware, steal customer data, and compromise user accounts. Search engines may also flag or delist your site if a breach occurs, devastating your traffic and SEO rankings.
Will upgrading break my website or plugins?
Modern WordPress versions are highly backward-compatible, but some very old plugins may have compatibility issues. This is why we recommend backing up your site first and testing plugins after the upgrade. Most users experience a smooth update with no problems, and our guide above provides safeguards to minimize risks.
How long does it take to upgrade WordPress 4.8?
The upgrade itself typically takes 2-5 minutes, though you should allocate additional time for backing up your site and testing plugins afterward. The entire process, done carefully, usually takes 15-30 minutes total. It's one of the best security investments you can make for your website.
Can I skip from WordPress 4.8 directly to the latest version?
Yes, WordPress allows direct upgrades across multiple versions. You don't need to update incrementally—you can jump straight from 4.8 to the current version. However, ensure you have a backup first, as this is a significant jump with many changes under the hood.
What is SQL injection and why is it dangerous?
SQL injection is when attackers insert malicious code into your website's database queries to steal, modify, or delete data. It's one of the most dangerous attack types because it gives attackers direct access to your customer information, passwords, and business-critical data without needing to crack any passwords.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com