Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 5.1
Security Advisory

WordPress 5.1 Security: 216 CVEs & How to Fix Them

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
18,472 websites still running wordpress 5.1  → View full list
216
Total
15
Critical
45
High
154
Medium
2
Low

WordPress 5.1 contains 216 documented vulnerabilities, including 15 critical flaws that could compromise your website's security. If you're running this outdated version, your site is at serious risk from hackers exploiting known security gaps. This guide shows you exactly what vulnerabilities exist and how to protect your website immediately.

Over 18,472 websites are still running WordPress 5.1, making it a prime target for cybercriminals. The vulnerabilities range from SQL injection attacks to authentication bypasses that could grant attackers complete control of your site. Understanding these risks is the first step toward securing your WordPress installation.

What is Wordpress 5.1?

WordPress 5.1 is an older version of WordPress, the platform that powers over 43% of all websites on the internet. Released in 2019, version 5.1 introduced improvements to editing functionality and site management tools. However, like all software, WordPress 5.1 has since been patched many times to fix security problems discovered by researchers and ethical hackers.

Think of WordPress versions like car models: newer versions get better safety features and fixes for discovered problems, while older models become increasingly vulnerable to new threats. WordPress 5.1 is now considered legacy software, meaning it's no longer actively maintained by the WordPress team. This means new security vulnerabilities discovered in plugins and the core system are no longer being patched for this version, leaving users exposed to known attacks.

Key Vulnerabilities in Wordpress 5.1

216 CVEs found. The most critical are explained below.

CRITICAL CVE-2021-24384 9.8/10 · CVSS v3.1 ⏱ Immediate
JoomSport Plugin - Attackers Can Inject Malicious Code

The JoomSport plugin has a security flaw that allows attackers to send specially crafted requests to your website. These requests can trick the plugin into executing harmful code without needing to log in first.

Impact: Attackers could take control of your website, steal data, or install malware that affects all your visitors.

↗ View on NVD
CRITICAL CVE-2022-0787 9.8/10 · CVSS v3.1 ⏱ Immediate
Login Attempts Plugin - SQL Database Attacks

The Limit Login Attempts plugin fails to properly validate user input in its security checks. Attackers can exploit this to directly access and manipulate your website's database.

Impact: Your customer data, passwords, and business information stored in the database could be stolen or deleted by attackers.

↗ View on NVD
CRITICAL CVE-2023-2986 9.8/10 · CVSS v3.1 ⏱ Immediate
Abandoned Cart Plugin - Fake Login Access

The Abandoned Cart plugin uses weak encryption for abandoned cart recovery links. Attackers can forge these links to log in as any customer without knowing their password.

Impact: Attackers can access customer accounts, view their personal information, and make purchases using their account or payment methods.

↗ View on NVD
CRITICAL CVE-2023-2437 9.8/10 · CVSS v3.1 ⏱ Immediate
UserPro Plugin - Facebook Login Bypass

The UserPro plugin doesn't properly verify users logging in through Facebook. Attackers can trick the plugin into thinking they are any user on your site.

Impact: Attackers can impersonate any user, including administrators, and gain full control of your website.

↗ View on NVD
CRITICAL CVE-2023-2449 9.8/10 · CVSS v3.1 ⏱ Immediate
UserPro Plugin - Unauthorized Password Reset

The UserPro plugin's password reset feature doesn't properly validate requests. Attackers can reset any user's password without permission.

Impact: Attackers can lock out legitimate users and take over accounts, including admin accounts with full website access.

↗ View on NVD
CRITICAL CVE-2024-2771 9.8/10 · CVSS v3.1 ⏱ Immediate
Fluent Forms Plugin - Unauthorized Admin Access

The Fluent Forms plugin has an API endpoint that doesn't check user permissions properly. Attackers can use this to gain administrative powers without being an admin.

Impact: Attackers could modify forms, access submissions containing customer data, or change website settings and content.

↗ View on NVD

Additional Vulnerabilities (210 more)

Showing first 10 of 210. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2024-11349 CRITICAL 9.8 2024-12-21 The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. This is due to the plugin not properly verifying a user's iden…
CVE-2024-11350 CRITICAL 9.8 2025-01-08 The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.1.6. This is due to the plugin not properly val…
CVE-2024-12857 CRITICAL 9.8 2025-01-22 The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's iden…
CVE-2025-2470 CRITICAL 9.8 2025-04-25 The Service Finder Bookings plugin for WordPress, used by the Service Finder - Directory and Job Board WordPress Theme, is vulnerable to privilege escalation in all versions up to…
CVE-2025-6715 CRITICAL 9.8 2025-08-13 The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes it possible for attackers to include and execute PHP files…
CVE-2026-1492 CRITICAL 9.8 2026-03-03 The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable …
CVE-2026-6510 CRITICAL 9.8 2026-05-14 The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. This is due to missing nonce v…
CVE-2026-5118 CRITICAL 9.8 2026-05-21 The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin accepting a user-controlled 'ro…
CVE-2026-6512 CRITICAL 9.1 2026-05-14 The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin not properly verifying that a …
CVE-2019-9787 HIGH 8.8 2019-03-14 WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF pro…
Full Report Available

All 216 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 5.1?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 5.1 is no longer safe for production websites. With 216 known vulnerabilities—including 15 critical flaws that could lead to complete site compromise—upgrading is not optional but essential. The good news is that updating takes just minutes and immediately closes the vast majority of these security holes.

Don't leave your website vulnerable to attacks. Use SiteRecipe.com to scan your WordPress installation for security vulnerabilities, outdated plugins, and misconfigurations. Our security experts can identify exactly which CVEs affect your site and provide step-by-step guidance to fix them. Start your free security audit today and protect your business from cyber threats.

Frequently Asked Questions

What happens if I don't update WordPress 5.1?
Your site becomes increasingly vulnerable to automated attacks exploiting known vulnerabilities. Hackers can inject malware, steal data, deface your website, or use your server to attack other sites. WordPress 5.1 is no longer receiving security patches, meaning any new vulnerabilities discovered will never be fixed on your version.
Will updating WordPress break my website?
Modern WordPress updates are designed to be backward compatible and rarely cause problems. However, some older custom themes or plugins might conflict with newer versions. This is why backing up your site first is crucial—if issues arise, you can restore from backup. Most sites update without any problems.
Is WordPress 5.1 completely unsupported?
Yes, WordPress 5.1 is no longer maintained by the WordPress security team. If a new vulnerability is discovered, it will not receive a patch. WordPress currently supports only the latest version and a few recent versions with security updates, making upgrading to a current version essential.
What's the difference between Critical and High severity CVEs?
Critical vulnerabilities can be exploited remotely without any user interaction and allow complete site takeover. High severity issues also pose serious risks but may require additional conditions to exploit. Both require immediate attention, but Critical vulnerabilities should be your top priority.
Can SiteRecipe.com help me fix these vulnerabilities?
Yes! SiteRecipe.com provides comprehensive WordPress security scanning that identifies which CVEs affect your specific installation, prioritizes them by severity, and provides detailed remediation steps tailored to your site.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com