Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 5.0.1
Security Advisory

WordPress 5.0.1: 48 Critical Vulnerabilities Explained

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
38 websites still running wordpress 5.0.1  → View full list
48
Total
8
Critical
8
High
30
Medium
2
Low

WordPress 5.0.1 contains 48 documented security vulnerabilities, with 8 classified as critical threats to your website. These flaws expose your site to unauthorized access, data breaches, and complete system compromise. If you're still running this outdated version, you're operating with a significant security risk that attackers actively exploit. Our comprehensive guide walks you through identifying vulnerabilities and implementing essential security patches to protect your WordPress installation from these dangerous exploits.

What is Wordpress 5.0.1?

WordPress 5.0.1 is an older version of WordPress, the world's most popular website building platform used by over 43% of all websites. Released in early 2019, this version introduced the block editor (Gutenberg) and various performance improvements. However, it was released before many critical security patches were developed and tested, leaving sites running this version vulnerable to modern attacks. WordPress 5.0.1 reached end-of-life years ago, meaning it no longer receives security updates from the official WordPress team. This means any vulnerabilities discovered after the version's release—and there have been many—remain unfixed unless you manually update your installation.

Key Vulnerabilities in Wordpress 5.0.1

48 CVEs found. The most critical are explained below.

CRITICAL CVE-2018-20148 9.8/10 · CVSS v3.0 ⏱ Immediate
WordPress Core - Unauthorized Access Through Media Files

WordPress 5.0.1 has a security flaw where contributors (lower-level users) can exploit how the system handles media file information. Attackers can inject malicious code through a specific technical request that manipulates how WordPress processes attached files.

Impact: An attacker could gain unauthorized access to your website and execute malicious code, potentially stealing data, modifying content, or taking over your entire WordPress installation.

↗ View on NVD
CRITICAL CVE-2017-18580 9.8/10 · CVSS v3.0 ⏱ Immediate
Shortcodes Ultimate Plugin - Code Execution Risk

The Shortcodes Ultimate plugin (before version 5.0.1) contains a critical flaw in how it processes shortcodes, which are small codes WordPress uses to add features. Attackers can exploit this to run their own code on your website.

Impact: Hackers can execute malicious commands on your server, compromise your database, steal customer information, or completely take over your website.

↗ View on NVD
CRITICAL CVE-2021-4073 9.8/10 · CVSS v3.1 ⏱ Immediate
RegistrationMagic Plugin - Anyone Can Log In as Admin

The RegistrationMagic plugin's social login feature has a flaw where it doesn't properly verify user identity. If someone knows a valid username (which is often public), they can log in as that user without a password.

Impact: Attackers can log in as administrators or any other user, giving them full control over your website, ability to modify content, access sensitive data, or delete everything.

↗ View on NVD
CRITICAL CVE-2023-6316 9.8/10 · CVSS v3.1 ⏱ Immediate
MW WP Form Plugin - Unauthorized File Upload Vulnerability

The MW WP Form plugin doesn't properly check what type of files users are uploading. This allows attackers to upload dangerous files (like executables) that shouldn't be allowed on your website.

Impact: Malicious files uploaded to your server can be executed to gain control of your website, steal data, or use your server for other attacks.

↗ View on NVD
CRITICAL CVE-2024-8911 9.8/10 · CVSS v3.1 ⏱ Immediate
LatePoint Plugin - User Password Hack via Database Manipulation

The LatePoint booking plugin has a flaw in how it processes database requests. An attacker can manipulate these requests to change any user's password, including administrator accounts.

Impact: Attackers can reset passwords for administrator accounts and gain complete control of your website without knowing the current password.

↗ View on NVD
CRITICAL CVE-2024-8943 9.8/10 · CVSS v3.1 ⏱ Immediate
LatePoint Plugin - Login Without Password

The LatePoint booking plugin doesn't properly verify that booking customers are who they claim to be. This allows anyone to log in as any existing user, including admins, without providing a password.

Impact: Unauthorized users can access admin accounts and gain full control of your website, customer data, and all business operations.

↗ View on NVD

Additional Vulnerabilities (42 more)

Showing first 10 of 42. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2019-25217 CRITICAL 9.8 2024-10-16 The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and Local File Inclusion in versions up to, and including, 5.0…
CVE-2025-7444 CRITICAL 9.8 2025-07-18 The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.0.1. This is due to insufficient verification on the user be…
CVE-2019-8942 HIGH 8.8 2019-02-20 WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending wit…
CVE-2023-2636 HIGH 8.8 2023-07-17 The AN_GradeBook WordPress plugin through 5.0.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by use…
CVE-2025-14124 HIGH 8.6 2026-01-05 The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users…
CVE-2026-2592 HIGH 7.7 2026-02-17 The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Update in all versions up to and including 5.0.16. This is due…
CVE-2018-20151 HIGH 7.5 2018-12-14 In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine …
CVE-2021-24862 HIGH 7.2 2022-01-10 The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in ba…
CVE-2025-2940 HIGH 7.2 2025-06-27 The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.18 via the args[url] paramet…
CVE-2026-1216 HIGH 7.2 2026-02-17 The RSS Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'template' parameter in all versions up to, and including, 5.0.10 due to insufficie…
Full Report Available

All 48 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 5.0.1?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 5.0.1 poses an unacceptable security risk with 48 known vulnerabilities waiting to be exploited. The 8 critical flaws alone could allow attackers to hijack your site, steal user data, and inject malicious code—compromising your business reputation and customer trust. Updating to the latest WordPress version is non-negotiable for any responsible website owner. SiteRecipe.com provides automated vulnerability scanning, one-click patching, and continuous security monitoring to keep your WordPress installation protected. Don't wait for a breach to happen—secure your site today with SiteRecipe's comprehensive security suite and stop worrying about version vulnerabilities forever.

Frequently Asked Questions

Is WordPress 5.0.1 still safe to use if I disable plugins?
No. WordPress 5.0.1 contains critical core vulnerabilities independent of plugins, including PHP object injection attacks and XMLRPC exploits. Disabling plugins provides minimal protection against core WordPress vulnerabilities. You must upgrade to a current version to be truly secure.
Will updating WordPress break my website?
Modern WordPress updates are designed to be backward compatible with properly coded themes and plugins. Always backup your site first, then update in a staging environment to test. Most updates complete seamlessly, and SiteRecipe can automate this process safely.
How often do new WordPress vulnerabilities appear?
WordPress releases security updates monthly, addressing newly discovered vulnerabilities. Running the latest version ensures you receive these patches automatically. Staying on version 5.0.1 means missing years of critical security improvements designed to protect against evolving attack methods.
Can attackers really exploit these CVEs on my site?
Yes. The 8 critical CVEs in 5.0.1 are actively exploited by automated attack bots scanning the internet for vulnerable sites. Attackers don't need advanced skills—they use publicly available exploit code targeting these exact vulnerabilities. Your site is a high-priority target.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com