Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 4.9.1
Security Advisory

WordPress 4.9.1 Security: 28 CVEs Explained & Fix Guide

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
120 websites still running wordpress 4.9.1  → View full list
28
Total
2
Critical
4
High
20
Medium
2
Low

WordPress 4.9.1 contains 28 known security vulnerabilities that could put your website at serious risk. With 2 critical-level CVEs and 4 high-severity issues, this outdated version is a target for hackers seeking unauthorized access and data theft. If your site is still running WordPress 4.9.1, you need to take action now to protect your business and customer data.

This comprehensive guide will help you understand the specific vulnerabilities affecting WordPress 4.9.1, identify if your site is at risk, and implement the security fixes needed to safeguard your WordPress installation. We'll walk you through each step of the process, from checking your current version to applying critical security patches.

What is Wordpress 4.9.1?

WordPress 4.9.1 is an older version of the popular WordPress content management system, released in 2017. At the time of its release, it was considered secure, but security researchers have since discovered multiple vulnerabilities that attackers can exploit. This version is still used by approximately 120 websites worldwide, many of which may be unaware of the security risks they're facing.

Think of WordPress 4.9.1 like an older model car—it worked great when it was new, but newer safety features and security systems have been developed since then. Running this outdated version is like driving without modern airbags and security systems. Hackers specifically target older WordPress versions because they know about these published vulnerabilities and can easily exploit them.

Key Vulnerabilities in Wordpress 4.9.1

28 CVEs found. The most critical are explained below.

CRITICAL CVE-2017-16562 9.8/10 · CVSS v3.0 ⏱ Immediate
UserPro Plugin Admin Bypass Vulnerability

The UserPro plugin has a security flaw that allows attackers to trick the system into thinking they are administrators without knowing the password. This happens if your site uses the common username 'admin' and the attacker modifies a specific web address parameter.

Impact: Hackers can gain complete control of your website, access all data, modify content, install malware, or lock you out of your own site.

↗ View on NVD
CRITICAL CVE-2023-5212 9.6/10 · CVSS v3.1 ⏱ Immediate
AI ChatBot Plugin Unauthorized File Deletion

The AI ChatBot plugin allows attackers with basic user accounts to delete any file on your server, not just their own files. Even regular subscribers can exploit this to destroy critical website files.

Impact: Your website could be completely destroyed or rendered non-functional. Attackers can delete backups, configuration files, and other essential data.

↗ View on NVD
HIGH CVE-2017-17091 8.8/10 · CVSS v3.0 ⏱ Immediate
WordPress User Creation Security Bypass

WordPress versions before 4.9.1 use a weak security code when creating new user accounts that attackers can easily guess. This allows unauthorized access to sensitive account creation functions.

Impact: Attackers can create fake admin accounts, add unauthorized users, or modify existing user permissions without authentication.

↗ View on NVD
HIGH CVE-2020-11026 8.7/10 · CVSS v3.1 ⏱ Within 7 days
Malicious File Upload Code Execution

Files with specially crafted names uploaded to your media library can execute malicious code when someone views them. This requires an attacker to already have upload permissions.

Impact: Attackers can run harmful code on your server, steal data, or use your website to attack visitors.

↗ View on NVD
HIGH CVE-2026-3222 7.5/10 · CVSS v3.1 ⏱ Within 7 days
WP Maps Plugin Database Injection Attack

The WP Maps plugin doesn't properly validate user input in the location search feature, allowing attackers to inject malicious database commands. They can slowly extract sensitive information from your database.

Impact: Hackers can access customer data, passwords, email addresses, and other sensitive information stored in your WordPress database.

↗ View on NVD
HIGH CVE-2026-2580 7.5/10 · CVSS v3.1 ⏱ Within 7 days
WP Maps Sort Feature Database Injection

The WP Maps Store Locator plugin has a flaw in its sorting feature that allows attackers to inject harmful database commands through the 'orderby' parameter.

Impact: Criminals can extract private customer information, database credentials, and other confidential data from your website.

↗ View on NVD

Additional Vulnerabilities (22 more)

Showing first 10 of 22. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2020-4047 MEDIUM 6.8 2020-06-12 In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way.…
CVE-2020-11030 MEDIUM 6.4 2020-04-30 In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authent…
CVE-2023-2300 MEDIUM 6.4 2023-06-03 The Contact Form Builder by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 4.9.1 due to insuff…
CVE-2020-11027 MEDIUM 6.1 2020-04-30 In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user…
CVE-2024-8850 MEDIUM 6.1 2024-09-19 The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' parameter when a placeholder such as {email} is used for th…
CVE-2024-12469 MEDIUM 6.1 2024-12-17 The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘status’ parameter in all versions up to, and…
CVE-2020-11025 MEDIUM 5.8 2020-04-30 In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires …
CVE-2020-11028 MEDIUM 5.8 2020-04-30 In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. This has been pat…
CVE-2020-11029 MEDIUM 5.8 2020-04-30 In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scripting (XSS) attacks. This has been…
CVE-2020-4048 MEDIUM 5.7 2020-06-12 In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect wh…
Full Report Available

All 28 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 4.9.1?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 4.9.1 contains serious security vulnerabilities that hackers actively exploit to gain unauthorized access to websites. The 2 critical vulnerabilities alone could allow attackers to delete your files or bypass authentication entirely. Staying on this outdated version puts your business reputation, customer trust, and sensitive data at serious risk.

Don't wait for a security breach to happen. Use SiteRecipe.com's free vulnerability scanner to instantly identify if your website is running outdated, vulnerable software. Our platform continuously monitors your site for security issues and alerts you to critical vulnerabilities before hackers can exploit them. Start your free security assessment today and get peace of mind knowing your WordPress installation is protected.

Frequently Asked Questions

What are the most dangerous CVEs affecting WordPress 4.9.1?
The two critical vulnerabilities are CVE-2017-16562 (UserPro plugin authentication bypass allowing admin access) and CVE-2023-5212 (AI ChatBot plugin arbitrary file deletion). These can give attackers complete control over your website or allow them to destroy your files. Combined with 4 high-severity CVEs, your site is extremely vulnerable to multiple attack vectors.
How long does it take to update WordPress 4.9.1 to the current version?
The update process typically takes 5-15 minutes depending on your site size and number of plugins. Most of this time is spent creating a backup and waiting for the WordPress update to complete. We recommend scheduling this during off-peak hours when fewer visitors are on your site.
Will updating WordPress break my plugins or themes?
Most modern plugins and themes are compatible with current WordPress versions, but older ones may have issues. This is why we recommend updating plugins and themes first, then backing up your site before updating WordPress. If problems occur, your backup allows you to quickly restore your site to its previous state.
Is WordPress 4.9.1 still receiving security updates?
No, WordPress 4.9.1 reached end-of-life years ago and receives no security patches. WordPress only supports the current version and one version back. Running 4.9.1 means you'll never receive protection against newly discovered vulnerabilities.
How can I prevent vulnerabilities in the future?
Always keep WordPress, plugins, and themes updated to their latest versions. Enable automatic updates if possible, or check for updates weekly. Use SiteRecipe.com to continuously scan your site for vulnerabilities and receive alerts about security issues before they become critical problems.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com