Home / Blog / wordpress 5.1
Security Advisory

WordPress 5.1: 215 CVEs Found - Security Update Guide 2024

📅 June 01, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
9,000 websites still running wordpress 5.1  → View full list
215
Total
15
Critical
45
High
153
Medium
2
Low

WordPress 5.1 is an older version of the world's most popular website platform, released in February 2019. If your website still runs this version, you're at significant risk: security researchers have identified 215 known vulnerabilities, including 15 critical flaws that could give attackers complete control of your site. These aren't theoretical threats—they're actively being exploited by cybercriminals targeting outdated WordPress installations.

The most dangerous vulnerabilities in WordPress 5.1 include authentication bypass flaws that let attackers log in without passwords, SQL injection attacks that expose your database, and privilege escalation exploits that give attackers admin access. With approximately 9,000 websites still running this vulnerable version, you may be at risk without even knowing it.

This guide will show you exactly how to identify if you're using WordPress 5.1, understand the specific threats you face, and take immediate action to protect your website and customer data.

What is Wordpress 5.1?

WordPress is the software that powers over 43% of all websites on the internet. It's a content management system (CMS) that lets you build and manage websites without needing to write code. WordPress 5.1, released in February 2019, is an older version that many website owners continue using either because they're unaware of security updates or they haven't migrated their sites yet. It handles everything from blog posts to e-commerce stores, making it a high-value target for hackers.

Just like your operating system (Windows, Mac, or Linux) needs regular updates to stay secure, WordPress requires consistent updates to patch newly discovered vulnerabilities. WordPress 5.1 is now five years old, meaning it predates many security discoveries and has been left without critical protective patches. Running outdated software is like leaving your front door unlocked—it's an open invitation to cybercriminals who know exactly which locks are broken.

Key Vulnerabilities in Wordpress 5.1

215 CVEs found. The most critical are explained below.

CRITICAL CVE-2021-24384 9.8/10 · CVSS v3.1 ⏱ Immediate
JoomSport Plugin Code Injection Vulnerability

The JoomSport plugin has a flaw that allows attackers to inject malicious code through a hidden data parameter. This vulnerability can be exploited without needing to log in to your WordPress site.

Impact: Attackers could take control of your website, steal sensitive data, or install malware that affects your visitors.

↗ View on NVD
CRITICAL CVE-2022-0787 9.8/10 · CVSS v3.1 ⏱ Immediate
Login Protection Plugin Database Injection Flaw

The Limit Login Attempts plugin fails to properly validate user input before using it in database queries. Attackers without login access can exploit this to manipulate your database directly.

Impact: Criminals could steal customer data, user credentials, or alter your website content and settings without authorization.

↗ View on NVD
CRITICAL CVE-2023-2986 9.8/10 · CVSS v3.1 ⏱ Immediate
Abandoned Cart Plugin Authentication Bypass

The Abandoned Cart Lite plugin uses weak encryption on recovery links, allowing attackers to forge valid links without a real password. This lets them access customer accounts they don't own.

Impact: Customer accounts could be compromised, leading to fraud, stolen payment information, or loss of trust in your store.

↗ View on NVD
CRITICAL CVE-2023-2437 9.8/10 · CVSS v3.1 ⏱ Immediate
UserPro Plugin Facebook Login Bypass

The UserPro plugin doesn't properly verify Facebook login details, allowing anyone to log in as any user without knowing their password. This completely bypasses your site's security.

Impact: Attackers can impersonate customers or administrators, access private information, and make unauthorized transactions or changes.

↗ View on NVD
CRITICAL CVE-2023-2449 9.8/10 · CVSS v3.1 ⏱ Immediate
UserPro Plugin Unprotected Password Reset

The UserPro plugin's password reset function lacks proper security checks, allowing attackers to reset any user's password without proper verification.

Impact: Any account on your site, including admin accounts, could be taken over by attackers who can then control your entire website.

↗ View on NVD
CRITICAL CVE-2024-2771 9.8/10 · CVSS v3.1 ⏱ Immediate
Fluent Forms Plugin Unauthorized Admin Access

The Fluent Forms plugin is missing a critical security check that allows regular users to access admin-only features through its API. Attackers can escalate their privileges without proper permissions.

Impact: Non-admin users or attackers could gain full administrative access to your website, allowing them to delete content, steal data, or lock you out.

↗ View on NVD

Additional Vulnerabilities (209 more)

Showing first 10 of 209. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2024-11349 CRITICAL 9.8 2024-12-21 The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. This is due to the plugin not properly verifying a user's iden…
CVE-2024-11350 CRITICAL 9.8 2025-01-08 The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.1.6. This is due to the plugin not properly val…
CVE-2024-12857 CRITICAL 9.8 2025-01-22 The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's iden…
CVE-2025-2470 CRITICAL 9.8 2025-04-25 The Service Finder Bookings plugin for WordPress, used by the Service Finder - Directory and Job Board WordPress Theme, is vulnerable to privilege escalation in all versions up to…
CVE-2025-6715 CRITICAL 9.8 2025-08-13 The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes it possible for attackers to include and execute PHP files…
CVE-2026-1492 CRITICAL 9.8 2026-03-03 The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable …
CVE-2026-6510 CRITICAL 9.8 2026-05-14 The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. This is due to missing nonce v…
CVE-2026-5118 CRITICAL 9.8 2026-05-21 The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin accepting a user-controlled 'ro…
CVE-2026-6512 CRITICAL 9.1 2026-05-14 The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin not properly verifying that a …
CVE-2019-9787 HIGH 8.8 2019-03-14 WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF pro…
Full Report Available

All 215 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

$1/report
⬇ Get Full Report — $1
PDF + HTML · Instant download

Is your website running Wordpress 5.1?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 5.1 exposes your website to 215 known security vulnerabilities, with 15 critical flaws that could result in complete compromise of your site, theft of customer data, or malware infections. The good news is that upgrading to a current version is straightforward and takes less than an hour. Every day you delay puts your business, your customers' information, and your reputation at risk.

Don't leave your website vulnerable to the hackers actively exploiting these flaws right now. Use SiteRecipe.com's security scanning tools to identify all vulnerabilities on your site, get step-by-step upgrade guidance tailored to your specific setup, and monitor your WordPress security continuously. Our platform makes it easy to stay protected so you can focus on growing your business instead of worrying about cyber attacks. Start your free security scan today at SiteRecipe.com.

Frequently Asked Questions

Is WordPress 5.1 still supported by Automattic?
No. WordPress 5.1 reached end-of-life in February 2020, meaning it no longer receives security patches or updates. Automattic officially recommends running WordPress 6.0 or later. Running unsupported versions puts you at severe risk since new vulnerabilities are discovered regularly but won't be patched for your version.
Will updating WordPress 5.1 break my plugins or theme?
Most modern plugins and themes are compatible with current WordPress versions, but some older add-ons may not be. This is why backing up before updating is critical. If incompatibilities occur, you can restore your backup and upgrade plugins/themes first, then try the WordPress update again. SiteRecipe.com can help identify compatibility issues before they happen.
Can I get hacked if I upgrade from WordPress 5.1?
Upgrading actually removes the vulnerabilities that hackers actively exploit, making your site significantly safer. However, ensure you only download WordPress from wordpress.org and keep all plugins/themes updated going forward. SiteRecipe.com provides ongoing monitoring to alert you to new threats before they become problems.
What's the most critical vulnerability in WordPress 5.1?
CVE-2021-24384 and CVE-2022-0787 are among the most dangerous, allowing attackers to inject malicious code or access your entire database without needing a password. CVE-2023-2437 and CVE-2023-2449 enable attackers to bypass authentication and reset admin passwords. These flaws affect plugin ecosystems that millions rely on, making them prime targets for automated attacks.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 01, 2026 · SiteRecipe.com