Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 4.8.9
Security Advisory

WordPress 4.8.9: 8 Critical Vulnerabilities Explained

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
1,408 websites still running wordpress 4.8.9  → View full list
8
Total
3
Critical
5
Medium

WordPress 4.8.9 contains 8 significant security vulnerabilities that put over 1,400 websites at risk. Three of these are classified as critical severity, including SQL injection, arbitrary file deletion, and directory traversal attacks that could compromise your entire site. If you're running this outdated version, immediate action is necessary to protect your data and your visitors' information.

This comprehensive guide will help you understand these vulnerabilities, determine if your site is affected, and implement the necessary security fixes. Whether you're a site owner or administrator, understanding these risks is the first step toward securing your WordPress installation.

What is Wordpress 4.8.9?

WordPress 4.8.9 is an older version of WordPress, the popular platform that powers nearly 44% of all websites on the internet. This particular version was released to address earlier security issues, but security researchers have since discovered that it still contains multiple unpatched vulnerabilities. Many websites continue running outdated versions like 4.8.9 either because they're unaware of the risks or they depend on plugins that haven't been updated for newer WordPress versions.

The vulnerabilities in WordPress 4.8.9 primarily affect the ChatBot and AI ChatBot plugins, which are commonly used to add automated customer support features to websites. These plugins allow attackers to inject malicious code, delete files, access sensitive information, or take unauthorized actions—even without proper administrator permissions. The severity of these issues makes upgrading or patching your WordPress installation a critical priority.

Key Vulnerabilities in Wordpress 4.8.9

8 CVEs found. The most critical are explained below.

CRITICAL CVE-2023-5204 9.8/10 · CVSS v3.1 ⏱ Immediate
ChatBot Plugin Database Attack Vulnerability

This vulnerability allows hackers to trick the ChatBot plugin into revealing or manipulating your website's database without needing to log in. They do this by sending specially crafted requests that bypass the plugin's security checks.

Impact: Attackers could steal customer data, passwords, email addresses, or modify your website's content and settings without your knowledge.

↗ View on NVD
CRITICAL CVE-2023-5212 9.6/10 · CVSS v3.1 ⏱ Immediate
ChatBot Plugin Allows File Deletion

This vulnerability lets anyone with even a basic subscriber account (like a commenter) delete critical files from your web server. The plugin doesn't properly check permissions before allowing file deletion.

Impact: Attackers could delete essential website files, causing your site to crash, become inaccessible, or allowing complete takeover of your website.

↗ View on NVD
CRITICAL CVE-2023-5241 9.6/10 · CVSS v3.1 ⏱ Immediate
ChatBot Plugin Path Traversal Attack

This flaw allows low-level users to access and modify files outside of where they should be allowed. They can insert malicious code into any file on your server by navigating through the file system.

Impact: Your website could be completely compromised, data stolen, or your site could be used to attack your visitors' computers.

↗ View on NVD
MEDIUM CVE-2022-4653 5.4/10 · CVSS v3.1 ⏱ Within 7 days
Greenshift Plugin XSS Script Injection

The Greenshift plugin doesn't properly filter user input in shortcodes, allowing contributors to inject malicious scripts. Once published, these scripts run for all visitors to your site.

Impact: Visitors' browsers could be infected with malware, their personal data stolen, or they could be redirected to malicious websites without your knowledge.

↗ View on NVD
MEDIUM CVE-2023-5254 5.3/10 · CVSS v3.1 ⏱ Within 7 days
ChatBot Plugin Leaks User Information

The ChatBot plugin unintentionally reveals whether specific usernames exist on your site. Hackers can use this information to target accounts for password attacks.

Impact: Your user accounts become easier targets for hackers attempting to break in, potentially compromising customer data and account security.

↗ View on NVD
MEDIUM CVE-2023-5533 5.3/10 · CVSS v3.1 ⏱ Immediate
ChatBot Plugin Missing Security Checks

The ChatBot plugin doesn't verify user permissions for certain automated actions. Unauthenticated visitors can trigger functions they shouldn't have access to.

Impact: Attackers could perform unauthorized actions on your site like modifying settings, deleting content, or accessing restricted information.

↗ View on NVD

Additional Vulnerabilities (2 more)

Showing first 10 of 2. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2023-5534 MEDIUM 4.3 2023-10-20 The AI ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.9 and 4.9.2. This is due to missing or incorrect nonce valida…
CVE-2025-12847 MEDIUM 4.3 2025-11-15 The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to unauthorized arbitrary media attachment deletion due to a m…
Full Report Available

All 8 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 4.8.9?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 4.8.9 poses serious security risks that cannot be ignored. With three critical vulnerabilities affecting SQL injection, file deletion, and directory traversal attacks, your website and user data are in danger. The good news is that these threats are completely preventable through timely updates and proper security practices. Taking action today protects not only your site but also your visitors' trust and your business reputation.

SiteRecipe.com provides automated security scanning and vulnerability detection to identify outdated software, missing patches, and potential threats across your entire web infrastructure. Our platform continuously monitors for new CVEs and alerts you immediately when vulnerabilities affecting your systems are discovered. Don't wait for a breach to happen—use SiteRecipe.com to proactively scan your websites and get detailed remediation guidance tailored to your specific setup. Start your free security scan today and gain peace of mind knowing your sites are protected.

Frequently Asked Questions

How did my site get WordPress 4.8.9 if it's so old?
WordPress 4.8.9 was released in 2017, and many sites haven't been updated since. This often happens when site owners are unaware of security updates, when hosting providers don't automatically update WordPress, or when sites depend on older plugins incompatible with newer WordPress versions. Regular updates should be part of your routine site maintenance.
Can attackers exploit these vulnerabilities without logging in?
Yes, some vulnerabilities like CVE-2023-5254 and CVE-2023-5533 allow unauthenticated attackers to exploit the site without any login credentials. Others require basic subscriber-level access. This makes the threats even more critical since attackers don't need to be insiders to cause damage.
Will updating WordPress break my site?
While updating is generally safe, compatibility issues can occasionally occur with older plugins or custom code. This is why we recommend creating a full backup before updating. Most modern plugins are designed to work with current WordPress versions, and the security benefits far outweigh the minimal risk of compatibility issues.
What if I can't update due to plugin incompatibility?
Contact your plugin developers for updated versions, or consider switching to actively-maintained alternatives. As a temporary measure, use security plugins like Wordfence to add additional protection layers, but this is not a permanent solution. Plugins that aren't updated regularly should be replaced to ensure long-term security.
How often should I check for WordPress vulnerabilities?
You should check at least monthly, but ideally enable automatic updates in WordPress settings. Security vulnerabilities are discovered continuously, and using automated scanning tools like SiteRecipe.com provides real-time alerts whenever new CVEs are disclosed that affect your systems.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com