Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 5.0.4
Security Advisory

WordPress 5.0.4 Security Vulnerabilities: 9 Critical Issues Found

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
2,943 websites still running wordpress 5.0.4  → View full list
9
Total
1
Critical
2
High
6
Medium

WordPress 5.0.4 is running on nearly 3,000 websites worldwide, but security researchers have discovered 9 significant vulnerabilities that put your site at serious risk. These flaws range from critical privilege escalation attacks to Cross-Site Request Forgery (CSRF) exploits that could compromise your data and user information. If you're still using this outdated version, it's time to take action and understand exactly what threats you're facing.

This comprehensive guide will walk you through identifying whether your site is vulnerable, understanding the specific threats, and implementing the security patches you need. We'll break down the technical details into simple terms so you can protect your WordPress installation immediately.

What is Wordpress 5.0.4?

WordPress 5.0.4 is a release of WordPress, the world's most popular website platform, that was launched several years ago. It powers content management for blogs, business websites, online stores, and more. While WordPress itself is powerful and flexible, each version receives security updates only for a limited time before support ends. Version 5.0.4 is now considered outdated, and running it exposes your website to known security threats that hackers actively exploit.

When WordPress releases a new version, it often includes patches for discovered vulnerabilities. Staying on older versions like 5.0.4 means you're missing these critical security fixes. Additionally, many popular plugins that work with WordPress (like contact forms, audio players, and video uploaders) have their own vulnerabilities when used with outdated WordPress versions. Combining old WordPress with vulnerable plugins creates multiple entry points for attacks.

Key Vulnerabilities in Wordpress 5.0.4

9 CVEs found. The most critical are explained below.

CRITICAL CVE-2018-20979 9.8/10 · CVSS v3.0 ⏱ Immediate
Contact Form 7 Plugin - Unauthorized Admin Access

The Contact Form 7 plugin before version 5.0.4 has a security flaw that allows attackers to gain administrative privileges they shouldn't have. This happens because the plugin doesn't properly check user permissions when managing forms.

Impact: An attacker could gain full control of your website, access sensitive data, modify content, or inject malicious code that affects your visitors.

↗ View on NVD
HIGH CVE-2023-6196 8.8/10 · CVSS v3.1 ⏱ Immediate
Audio Merchant Plugin - Unauthorized File Uploads

The Audio Merchant plugin before version 5.0.4 is missing security checks that prevent unauthorized file uploads. An attacker can trick your website into uploading malicious files without needing to log in.

Impact: Attackers could upload harmful files to your server that could compromise your website's security, inject malware, or be used to attack your visitors.

↗ View on NVD
HIGH CVE-2025-14390 8.8/10 · CVSS v3.1 ⏱ Immediate
Video Merchant Plugin - Unauthorized File Uploads

The Video Merchant plugin version 5.0.4 and earlier lacks proper security validation for file uploads. Attackers can exploit this to upload malicious files to your website without authentication.

Impact: Unauthorized files could be uploaded to your server, potentially containing malware or code that compromises your site and enables remote attacks.

↗ View on NVD
MEDIUM CVE-2023-6993 6.4/10 · CVSS v3.1 ⏱ Within 7 days
Custom Post Types Plugin - Malicious Script Injection

The Custom Post Types plugin before version 5.0.4 doesn't properly filter user input in custom fields. This allows attackers to inject malicious scripts that execute when others view the page.

Impact: Visitors to your site could have their data stolen, be redirected to malicious sites, or have their browsers infected with malware.

↗ View on NVD
MEDIUM CVE-2021-24128 5.4/10 · CVSS v3.1 ⏱ Within 7 days
Team Members Plugin - Script Injection by Contributors

The Team Members plugin before version 5.0.4 allows contributors or editors to inject malicious code through member biographies. This code runs when visitors view those profiles.

Impact: A compromised team member account could inject malware or steal visitor data, requiring you to remove the malicious content and audit your accounts.

↗ View on NVD
MEDIUM CVE-2023-6197 5.4/10 · CVSS v3.1 ⏱ Within 7 days
Audio Merchant Plugin - Plugin Settings Hijacking

The Audio Merchant plugin before version 5.0.4 has missing security checks on its settings page. Attackers can trick your website into changing plugin settings without your permission.

Impact: Attackers could modify audio player settings, redirect users to malicious sites, or inject advertisements and malicious content into your audio player.

↗ View on NVD

Additional Vulnerabilities (3 more)

Showing first 10 of 3. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2024-5449 MEDIUM 4.3 2024-06-06 The WP Dark Mode – WordPress Dark Mode Plugin for Improved Accessibility, Dark Theme, Night Mode, and Social Sharing plugin for WordPress is vulnerable to unauthorized modificatio…
CVE-2024-8432 MEDIUM 4.3 2024-09-24 The Appointment & Event Booking Calendar Plugin – Webba Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sa…
CVE-2025-11742 MEDIUM 4.3 2025-10-18 The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wishlist_quickview' AJAX action …
Full Report Available

All 9 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 5.0.4?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 5.0.4 contains 9 documented security vulnerabilities—1 critical, 2 high-severity, and 6 medium-severity—that affect thousands of websites. The most dangerous vulnerability is CVE-2018-20979, a critical privilege escalation flaw in the Contact Form 7 plugin that could allow attackers to gain unauthorized admin access to your site. Delayed patching puts your website, your users' data, and your business reputation at serious risk.

Don't leave your WordPress site exposed to these known threats. Visit SiteRecipe.com today to scan your website for vulnerabilities, get detailed security recommendations, and receive step-by-step guidance on patching your specific WordPress version. Our security experts can help you identify which of these 9 CVEs affect your site and implement fixes quickly. Start your free security assessment now and protect your WordPress installation before attackers do.

Frequently Asked Questions

Is WordPress 5.0.4 still supported with security updates?
No. WordPress only provides security updates for recent versions. Version 5.0.4 reached end-of-life years ago and no longer receives patches. You must upgrade to a current version like 6.4 or later to receive ongoing security support and protect your site.
Can I update WordPress without losing my content or settings?
Yes, absolutely. WordPress updates preserve all your content, pages, posts, and plugin settings. Always create a backup before updating as a precaution, but updates are designed to be safe. The process typically takes just a few minutes and can be done directly from your admin dashboard.
What happens if hackers exploit these WordPress 5.0.4 vulnerabilities?
Attackers could gain admin access to your site, inject malware, steal user data, deface your pages, or use your server to attack other websites. The critical CVE-2018-20979 vulnerability specifically allows privilege escalation, meaning someone could take control of your entire WordPress installation without having legitimate login credentials.
How do I know which plugins have vulnerabilities in my WordPress 5.0.4 installation?
The main vulnerable plugins for version 5.0.4 include Contact Form 7, Audio Merchant, Video Merchant, Team Members, and Custom post types plugins. Check your Plugins page to see if you're running these. You can also use SiteRecipe.com's security scanner to identify all vulnerabilities specific to your site's configuration.
Will updating WordPress break my custom code or themes?
Most updates are backward-compatible and won't affect properly-coded custom themes or plugins. However, very old custom code might have compatibility issues. This is why we recommend backing up before updating and testing your site afterward. If problems occur, your backup allows you to revert quickly.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com