Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 5.0
Security Advisory

WordPress 5.0 Security: 161 CVEs Explained & How to Fix

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
29 websites still running wordpress 5.0  → View full list
161
Total
15
Critical
28
High
115
Medium
3
Low

WordPress 5.0 remains one of the most vulnerable versions still in use, with 161 documented security flaws affecting 29 known websites. Among these, 15 critical vulnerabilities pose serious risks including remote code execution, SQL injection, and unauthorized admin access. If your site still runs WordPress 5.0, you're operating with significant security exposure that hackers actively exploit.

This comprehensive guide explains the major vulnerabilities in WordPress 5.0, shows you how to determine if your site is at risk, and provides clear steps to secure your installation. Whether you're a business owner or webmaster, understanding these threats is essential for protecting your website and user data.

What is Wordpress 5.0?

WordPress 5.0 was released in December 2018 as a major update introducing the Gutenberg block editor. This version represented a significant shift in how content creators build pages and posts, offering more visual flexibility and control. However, this substantial code overhaul also introduced numerous security gaps that weren't immediately apparent to everyday users.

Unlike newer WordPress versions with regular security patches, WordPress 5.0 reached end-of-life years ago, meaning it no longer receives official security updates. This creates a dangerous situation where known vulnerabilities remain unpatched, making sites running this version attractive targets for cybercriminals. The 161 identified CVEs (Common Vulnerabilities and Exposures) range from password bypass flaws to complete website takeover scenarios.

Key Vulnerabilities in Wordpress 5.0

161 CVEs found. The most critical are explained below.

CRITICAL CVE-2018-20148 9.8/10 · CVSS v3.0 ⏱ Immediate
WordPress Core - Attackers Can Inject Malicious Code

A vulnerability in WordPress 5.0 and earlier allows attackers to inject harmful code through media file requests. This happens because WordPress doesn't properly check the data it receives when you interact with images and media files.

Impact: An attacker could take control of your website, steal data, or install malware without needing your password.

↗ View on NVD
CRITICAL CVE-2018-20979 9.8/10 · CVSS v3.0 ⏱ Immediate
Contact Form 7 Plugin - Unauthorized Access Risk

The popular Contact Form 7 plugin has a flaw that lets users gain more permissions than they should have. Even low-level contributors could perform admin-level actions on your site.

Impact: Someone with basic website access could delete content, modify settings, or compromise your entire website.

↗ View on NVD
CRITICAL CVE-2017-18580 9.8/10 · CVSS v3.0 ⏱ Immediate
Shortcodes Ultimate Plugin - Website Code Execution

The Shortcodes Ultimate plugin contains a serious flaw that allows attackers to run harmful code on your website. They can exploit how the plugin processes shortcodes without proper safety checks.

Impact: Your website could be completely compromised, allowing attackers to steal all data, deface your site, or use it for attacks.

↗ View on NVD
CRITICAL CVE-2021-24866 9.8/10 · CVSS v3.1 ⏱ Immediate
WP Data Access Plugin - Database Attack Vulnerability

The WP Data Access plugin doesn't properly secure search parameters, allowing attackers to inject malicious database commands. Someone could delete your entire database without authentication.

Impact: Your website's database could be deleted or corrupted, resulting in complete loss of all website data and functionality.

↗ View on NVD
CRITICAL CVE-2021-4073 9.8/10 · CVSS v3.1 ⏱ Immediate
RegistrationMagic Plugin - Admin Account Takeover

The RegistrationMagic plugin's social login feature has a critical flaw where anyone can log in as any user—including administrators—if they know a valid username. No password verification is required.

Impact: Attackers could gain full administrator access to your website and complete control over all content, settings, and user data.

↗ View on NVD
CRITICAL CVE-2021-24949 9.8/10 · CVSS v3.1 ⏱ Immediate
Plus Addons for Elementor - Database Manipulation Attack

The WP Search Filters widget in Plus Addons doesn't properly validate search inputs, allowing attackers to inject database commands. This lets them access or modify sensitive database information.

Impact: Attackers could steal all your website data, modify records, or delete important information from your database.

↗ View on NVD

Additional Vulnerabilities (155 more)

Showing first 10 of 155. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2022-0320 CRITICAL 9.8 2022-02-01 The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data before it them in include statements, which could allow unauthen…
CVE-2023-6316 CRITICAL 9.8 2024-01-11 The MW WP Form plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the '_single_file_upload' function in versions up to, and i…
CVE-2024-8911 CRITICAL 9.8 2024-10-08 The LatePoint plugin for WordPress is vulnerable to Arbitrary User Password Change via SQL Injection in versions up to, and including, 5.0.11. This is due to insufficient escaping…
CVE-2024-8943 CRITICAL 9.8 2024-10-08 The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. This is due to insufficient verification on the user being sup…
CVE-2019-25217 CRITICAL 9.8 2024-10-16 The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and Local File Inclusion in versions up to, and including, 5.0…
CVE-2024-13442 CRITICAL 9.8 2025-03-19 The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.0. This is due to the plugin no…
CVE-2025-5746 CRITICAL 9.8 2025-07-02 The Drag and Drop Multiple File Upload (Pro) - WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the dnd_upload_cf7_u…
CVE-2025-7444 CRITICAL 9.8 2025-07-18 The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.0.1. This is due to insufficient verification on the user be…
CVE-2024-12626 CRITICAL 9.6 2024-12-19 The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th…
CVE-2019-8942 HIGH 8.8 2019-02-20 WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending wit…
Full Report Available

All 161 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 5.0?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 5.0's 161 vulnerabilities—including 15 critical flaws that allow complete site takeover—represent a serious security risk that demands immediate action. Delaying updates exposes your website, customer data, and reputation to active exploitation by cybercriminals. The good news is that upgrading to a current WordPress version resolves virtually all known issues and takes just minutes to complete.

Don't leave your business vulnerable another day. Use SiteRecipe.com's security scanning and monitoring tools to identify vulnerabilities across your WordPress installation, track your plugin versions, and receive alerts about new threats. Our platform makes it simple to stay secure with automated update tracking and comprehensive vulnerability reports. Visit SiteRecipe.com today to scan your site for free and protect what matters most.

Frequently Asked Questions

Is WordPress 5.0 still safe to use in 2024?
No. WordPress 5.0 reached end-of-life and no longer receives security updates, leaving it vulnerable to all 161 known CVEs. Even if you've patched your plugins, the WordPress core itself contains unpatched critical flaws. Upgrading to WordPress 6.4+ is essential for any production website.
Can I be hacked if I update my plugins but not WordPress core?
Yes. Many of the critical WordPress 5.0 vulnerabilities exist in the core WordPress files, not plugins. CVE-2018-20148, for example, is a PHP object injection flaw in WordPress core that allows attackers to execute arbitrary code regardless of your plugins' security status. Core updates are non-negotiable.
Will updating WordPress break my site or lose my content?
Modern WordPress updates are designed to be backward compatible and won't delete your content. However, you should always backup before updating, and test on a staging environment first if you have custom code. Most sites update without any issues when proper backups are in place.
How long does it take to update from WordPress 5.0?
The WordPress core update typically takes 2-5 minutes and requires just one click from your Dashboard. Plugin updates take a few more minutes. The entire process usually completes in under 15 minutes, but you should allocate an hour including backup and testing to be safe.
What should I do if I find malware after being on WordPress 5.0?
First, restore from your most recent clean backup before the infection date if possible. If you don't have a backup, use a malware removal service like Sucuri or Wordfence to clean your site. Then update everything and implement security monitoring to prevent re-infection.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com