Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 4.9.2
Security Advisory

WordPress 4.9.2: 22 Critical Vulnerabilities You Must Fix Now

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
53 websites still running wordpress 4.9.2  → View full list
22
Total
2
Critical
2
High
18
Medium

WordPress 4.9.2 contains 22 known security vulnerabilities that put your website at serious risk. Two of these are classified as CRITICAL, meaning attackers can exploit them to delete files, access sensitive data, and compromise your entire site. If you're still running this outdated version, your website is a target.

With 53 websites still using WordPress 4.9.2, many site owners are unaware of the dangers lurking in their installations. The vulnerabilities range from arbitrary file deletion to directory traversal attacks that allow unauthorized access. This guide will help you identify if your site is vulnerable and show you exactly how to fix it.

What is Wordpress 4.9.2?

WordPress 4.9.2 is an older release of WordPress, the world's most popular website platform. Released in January 2018, it powered millions of websites at the time. However, like all software, WordPress receives security updates to patch newly discovered vulnerabilities. Version 4.9.2 is now several years old and no longer receives official security patches from WordPress.org.

Running outdated WordPress versions is like leaving your front door unlocked. Hackers actively exploit known vulnerabilities in older versions because they know many site owners haven't updated. The 22 vulnerabilities in WordPress 4.9.2—including critical flaws in file handling and authentication—make this version particularly dangerous for any site still in use.

Key Vulnerabilities in Wordpress 4.9.2

22 CVEs found. The most critical are explained below.

CRITICAL CVE-2023-5212 9.6/10 · CVSS v3.1 ⏱ Immediate
AI ChatBot Plugin - Attackers Can Delete Your Files

The AI ChatBot plugin has a serious flaw that lets people with basic user accounts delete important files from your website server. This is like giving someone a key to delete critical documents in your office.

Impact: An attacker could delete essential website files, causing your site to go down completely or allowing them to take full control of your WordPress installation.

↗ View on NVD
CRITICAL CVE-2023-5241 9.6/10 · CVSS v3.1 ⏱ Immediate
AI ChatBot Plugin - Attackers Can Inject Malicious Code

The AI ChatBot plugin allows basic users to sneak malicious code into your website files through a file upload feature. It's like someone finding a back door to your house and leaving traps inside.

Impact: Your website could crash, become slow, or be used to attack visitors and spread malware.

↗ View on NVD
HIGH CVE-2024-31210 7.6/10 · CVSS v3.1 ⏱ Within 7 days
WordPress - Non-Zip Files Can Be Uploaded as Plugins

WordPress doesn't properly check if uploaded plugin files are legitimate, allowing administrators to accidentally upload dangerous files. This is like a security guard not checking if a package contains what it claims.

Impact: Your site could be compromised if you or someone with admin access unknowingly uploads a malicious file disguised as a plugin.

↗ View on NVD
HIGH CVE-2018-6389 7.5/10 · CVSS v3.0 ⏱ Within 7 days
WordPress - Attackers Can Overload Your Website

Anyone on the internet can repeatedly request large numbers of JavaScript files from your WordPress site without logging in, using up your server resources. It's like thousands of people flooding your store at once.

Impact: Your website becomes very slow or completely unavailable, hurting your business and visitor experience.

↗ View on NVD
MEDIUM CVE-2024-12558 6.5/10 · CVSS v3.1 ⏱ Within 30 days
Booking Plugin - Unauthorized Access to Database

The WP BASE Booking plugin doesn't properly check user permissions when exporting data, allowing basic users to access sensitive information. Like a receptionist having access to your financial records.

Impact: Private booking information, customer data, or business details could be viewed or downloaded by unauthorized users.

↗ View on NVD
MEDIUM CVE-2018-5776 6.1/10 · CVSS v3.0 ⏱ Within 30 days
WordPress - Video Player Security Weakness

WordPress's built-in video player has a flaw that allows attackers to inject harmful code through specially crafted requests. This affects how videos are displayed on your site.

Impact: Visitors' browsers could be exploited, potentially stealing their personal information or redirecting them to malicious sites.

↗ View on NVD

Additional Vulnerabilities (16 more)

Showing first 10 of 16. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2018-16285 MEDIUM 6.1 2018-09-06 The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template action to wp-admin/admin-ajax.php.
CVE-2023-1978 MEDIUM 6.1 2023-06-09 The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the query string in versions up to, and including, 4.9.25 du…
CVE-2025-5807 MEDIUM 6.1 2025-07-10 The Gwolle Guestbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘gwolle_gb_content’ parameter in all versions up to, and including, 4.9.2 due to ins…
CVE-2025-58674 MEDIUM 5.9 2025-09-23 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows Stored XSS. WordPress core security team is aware of the iss…
CVE-2023-5533 MEDIUM 5.3 2023-10-20 The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks on the corresponding functions in versions up to, and includ…
CVE-2025-10637 MEDIUM 5.3 2025-10-25 The Social Feed Gallery plugin for WordPress is vulnerable to Information Exposure in versions less than, or equal to, 4.9.2. This is due to the plugin not properly verifying that…
CVE-2025-14442 MEDIUM 5.3 2025-12-12 The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to sensitive information exposure due to storage of exported CSV files in a publicly acce…
CVE-2024-32111 MEDIUM 5.0 2024-06-25 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic WordPress allows Relative Path Traversal.This issue affects WordPress: f…
CVE-2025-1453 MEDIUM 4.8 2025-04-24 The Category Posts Widget WordPress plugin before 4.9.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored …
CVE-2023-39999 MEDIUM 4.3 2023-10-13 Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 thr…
Full Report Available

All 22 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 4.9.2?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 4.9.2 is no longer safe to use in 2024. With 22 known vulnerabilities—including two critical exploits that allow file deletion and unauthorized access—staying on this version invites disaster. The good news is that updating to the latest WordPress version takes just minutes and immediately patches the majority of these threats.

Don't wait for a breach to happen. Use SiteRecipe.com's vulnerability scanner to identify all security risks on your website, get step-by-step remediation guides, and monitor for new threats continuously. Our platform makes WordPress security simple, even for non-technical site owners. Scan your site today and sleep better knowing you're protected.

Frequently Asked Questions

Is WordPress 4.9.2 still supported with security updates?
No. WordPress 4.9.2 was released in January 2018 and reached end-of-life years ago. WordPress only supports the current version and a few previous releases with security patches. Any version older than approximately 2-3 releases behind the current version will not receive official security updates.
Can I update WordPress without losing my content?
Yes, absolutely. WordPress updates preserve all your posts, pages, comments, and settings. Before updating, always create a backup of your site. After the update completes, verify that your site looks and functions correctly. Most sites experience no issues during WordPress updates.
What happens if I don't update from WordPress 4.9.2?
Your site becomes increasingly vulnerable to automated attacks. Hackers use tools to scan the internet for outdated WordPress versions and exploit known vulnerabilities. You risk data theft, malware infection, website defacement, or complete takeover. Additionally, your site may be blacklisted by search engines if it's compromised.
Does SiteRecipe.com help with WordPress updates?
SiteRecipe.com identifies all vulnerabilities in your WordPress installation and provides clear guidance on fixes. While we don't automatically apply updates, our platform tells you exactly what needs updating, in what order, and flags any compatibility issues before they become problems.
Are there any risks to updating WordPress?
While WordPress updates are generally very safe, there's a small risk that incompatible plugins or themes could break after an update. This is why backups are essential. Test updates on a staging environment first if possible, or update during low-traffic hours so you can quickly resolve any issues.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com