WordPress 5.2, released in 2019, contains 133 known security vulnerabilities that put your website at serious risk. Among these are 9 critical CVEs that could allow attackers to take control of your site, steal data, or inject malicious code. An estimated 9,000 websites still run this outdated version, making them prime targets for cybercriminals.
The most dangerous vulnerabilities in WordPress 5.2 include Server-Side Request Forgery (SSRF) attacks and SQL injection flaws through popular plugins. These aren't theoretical threatsāthey're being actively exploited in the wild. If your site hasn't been updated, you could be compromised without even knowing it.
This guide explains what WordPress 5.2 vulnerabilities are, how to check if your site is at risk, and the exact steps to secure your installation.
WordPress 5.2 is a version of WordPress released in May 2019. WordPress is the content management system that powers over 43% of all websites on the internet. Think of it as the "engine" that runs your blog, business website, or online store. WordPress 5.2 was a major release that introduced new features and improvements, but it also contained security weaknesses that weren't fully understood at the time.
Vulnerabilities are like unlocked doors in your website's security system. Attackers can exploit these weaknesses to break in, steal customer information, display malware, or take complete control of your site. WordPress 5.2's 133 vulnerabilitiesāespecially the 9 critical onesāare like having 9 completely unlocked front doors while intruders are actively trying to break in. The good news: these vulnerabilities are fixable with updates.
133 CVEs found. The most critical are explained below.
WordPress has a security weakness in how it validates website addresses. Attackers can trick your WordPress site into making requests to internal systems or other websites by using special character formats that bypass the safety checks.
Impact: An attacker could potentially access sensitive internal data, files, or systems connected to your website that should be private.
ā View on NVDWordPress doesn't properly handle Windows file paths when checking if URLs are safe. This allows attackers to bypass security checks and make your server request restricted content.
Impact: Attackers could gain unauthorized access to internal systems, files, or sensitive information stored on your server.
ā View on NVDThe Zero Spam plugin has a flaw where it doesn't properly clean user input before searching your database. Attackers can inject malicious code into search parameters to access or manipulate your database.
Impact: Hackers could steal, modify, or delete important website data, or gain access to sensitive information like user details.
ā View on NVDThe SiteSuperCharger plugin doesn't validate user inputs before using them in database queries. Anyone, including people without login access, can exploit this to inject harmful database commands.
Impact: Attackers could completely compromise your website data, steal user information, modify content, or take full control of your site.
ā View on NVDThe Newspaper and Newsmag themes have a broken Facebook login feature that doesn't properly verify user identity. Attackers can fake being any user by just knowing their email address.
Impact: Anyone could log into user accounts without knowing passwords, gaining access to private information and the ability to impersonate other users.
ā View on NVDThe JoomSport plugin fails to properly clean user input before using it in database commands. Attackers can inject malicious code to access or manipulate your database without needing any special access.
Impact: Hackers could steal sensitive data, modify website content, create fake accounts, or take control of your entire WordPress site.
ā View on NVDShowing first 10 of 127. View all on NVD ā
| CVE ID | Severity | Score | Published | Description |
|---|---|---|---|---|
| CVE-2023-2499 | CRITICAL | 9.8 | 2023-05-16 | The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.1.0. This is due to insufficient verification on the user b⦠|
| CVE-2024-12922 | CRITICAL | 9.8 | 2025-03-19 | The Altair theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check within functions.php in a⦠|
| CVE-2019-25224 | CRITICAL | 9.8 | 2025-07-25 | The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated atta⦠|
| CVE-2019-17675 | HIGH | 8.8 | 2019-10-17 | WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF. |
| CVE-2021-25051 | HIGH | 8.8 | 2022-01-10 | The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// pro⦠|
| CVE-2025-2319 | HIGH | 8.8 | 2025-03-25 | The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.11.13 to 5.25.08. This is due to missing or incorr⦠|
| CVE-2026-1566 | HIGH | 8.8 | 2026-03-03 | The LatePoint ā Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and includ⦠|
| CVE-2020-11026 | HIGH | 8.7 | 2020-04-30 | In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an au⦠|
| CVE-2024-6420 | HIGH | 8.6 | 2024-07-23 | The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to a⦠|
| CVE-2022-0403 | HIGH | 8.1 | 2022-04-04 | The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security issues (CVE-2021-32682), and ⦠|
| CVE-2024-10783 | HIGH | 8.1 | 2024-12-13 | The MainWP Child ā Securely Connects to the MainWP Dashboard to Manage Multiple Sites plugin for WordPress is vulnerable to privilege escalation due to a missing authorization che⦠|
| CVE-2024-31210 | HIGH | 7.6 | 2024-04-04 | WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plugin by an administrative user on the Plu⦠|
| CVE-2012-6707 | HIGH | 7.5 | 2017-10-19 | WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values⦠|
| CVE-2019-17673 | HIGH | 7.5 | 2019-10-17 | WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header. |
| CVE-2024-5598 | HIGH | 7.5 | 2024-06-29 | The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.4 via the 'fma_local_file_system' function⦠|
| CVE-2024-8126 | HIGH | 7.5 | 2024-09-26 | The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.8. This mak⦠|
| CVE-2024-11391 | HIGH | 7.5 | 2024-12-03 | The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connector.php' file in all versions u⦠|
| CVE-2024-13333 | HIGH | 7.5 | 2025-01-17 | The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fma_local_file_system' function in versions 5.2.⦠|
| CVE-2024-13534 | HIGH | 7.5 | 2025-02-19 | The Small Package Quotes ā Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to,⦠|
| CVE-2025-11517 | HIGH | 7.5 | 2025-10-18 | The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 5.26.5. This is due to the /wp-json/tribe/tickets/v1/⦠|
| CVE-2026-7459 | HIGH | 7.5 | 2026-05-30 | The Simple History ā Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to authenticated (Subscriber+) account takeover in all versions up to, and includin⦠|
| CVE-2022-2717 | HIGH | 7.2 | 2022-09-06 | The JoomSport ā for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-events-form pag⦠|
| CVE-2022-2718 | HIGH | 7.2 | 2022-09-06 | The JoomSport ā for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter on the joomsport-page-extrafield⦠|
| CVE-2024-8704 | HIGH | 7.2 | 2024-09-26 | The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the 'fma_locale' parameter. This ma⦠|
| CVE-2024-9548 | HIGH | 7.2 | 2024-10-15 | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in all versions up to, and including, 5.2.6 due to insufficient⦠|
| CVE-2024-10793 | HIGH | 7.2 | 2024-11-15 | The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and including, 5.2.1 due to insufficient inp⦠|
| CVE-2024-10646 | HIGH | 7.2 | 2024-12-14 | The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form's subject ⦠|
| CVE-2024-13351 | HIGH | 7.2 | 2025-01-15 | The Social proof testimonials and reviews by Repuso plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rw_image_badge1' shortcode in all versions ⦠|
| CVE-2025-0924 | HIGH | 7.2 | 2025-02-17 | The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the āmessageā parameter in all versions up to, and including, 5.2.2 due to insufficient i⦠|
| CVE-2025-5487 | HIGH | 7.2 | 2025-06-14 | The AutomatorWP ā Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the fiel⦠|
| CVE-2026-0617 | HIGH | 7.2 | 2026-02-03 | The LatePoint ā Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer profile fields in all versio⦠|
| CVE-2026-1843 | HIGH | 7.2 | 2026-02-14 | The Super Page Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Activity Log in all versions up to, and including, 5.2.2 due to insufficient input s⦠|
| CVE-2013-2107 | MEDIUM | 6.8 | 2014-05-23 | Cross-site request forgery (CSRF) vulnerability in the Mail On Update plugin before 5.2.0 for WordPress allows remote attackers to hijack the authentication of administrators for ⦠|
| CVE-2020-4047 | MEDIUM | 6.8 | 2020-06-12 | In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way.⦠|
| CVE-2022-29448 | MEDIUM | 6.8 | 2022-05-20 | Authenticated (admin or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Herd Effects plugin <= 5.2 at WordPress. |
| CVE-2025-12136 | MEDIUM | 6.8 | 2025-10-24 | The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.2.4. This is due t⦠|
| CVE-2023-2548 | MEDIUM | 6.6 | 2023-05-16 | The RegistrationMagic plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 5.2.0.5. This is due to the plugin providing user-c⦠|
| CVE-2022-1422 | MEDIUM | 6.5 | 2022-06-08 | The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an attacker to trick an admin into resetting the site settings⦠|
| CVE-2026-1487 | MEDIUM | 6.5 | 2026-03-03 | The LatePoint ā Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to SQL Injection via the JSON Import in all versions up to, and including, 5⦠|
| CVE-2020-11030 | MEDIUM | 6.4 | 2020-04-30 | In affected versions of WordPress, a special payload can be crafted that can lead to scripts getting executed within the search block of the block editor. This requires an authent⦠|
| CVE-2024-5218 | MEDIUM | 6.4 | 2024-05-25 | The Reviews and Rating ā Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions up to, and including⦠|
| CVE-2024-12500 | MEDIUM | 6.4 | 2024-12-18 | The Philantro ā Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes like 'donate' in all versions up to, a⦠|
| CVE-2024-13803 | MEDIUM | 6.4 | 2025-02-26 | The Essential Blocks ā Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ādata-markerā parameter in all⦠|
| CVE-2024-13805 | MEDIUM | 6.4 | 2025-03-07 | The Advanced File Manager ā Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in a⦠|
| CVE-2025-6462 | MEDIUM | 6.4 | 2025-06-29 | The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's SQLREPORT shortcode in all versions up to, and⦠|
| CVE-2025-8902 | MEDIUM | 6.4 | 2025-09-23 | The Widget Options - Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'do_sidebar' shortcode in all versions up to, and including, 5.2.1⦠|
| CVE-2025-7400 | MEDIUM | 6.4 | 2025-10-07 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a post's Featured Image custom fields in all versions up to, and including⦠|
| CVE-2025-13135 | MEDIUM | 6.4 | 2025-11-21 | The HotelRunner Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hotelrunner' shortcode in all versions up to, and including, 5.2⦠|
| CVE-2025-13853 | MEDIUM | 6.4 | 2026-01-09 | The Nearby Now Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_tech' parameter of the nn-tech shortcode in all versions up to, and includin⦠|
| CVE-2026-0552 | MEDIUM | 6.4 | 2026-04-04 | The Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsc_display_product' shortcode in all versions up to, and including, ⦠|
| CVE-2009-5158 | MEDIUM | 6.1 | 2019-08-22 | The google-analyticator plugin before 5.2.1 for WordPress has insufficient HTML sanitization for Google Analytics API text. |
| CVE-2018-20983 | MEDIUM | 6.1 | 2019-08-22 | The wp-retina-2x plugin before 5.2.3 for WordPress has XSS. |
| CVE-2019-16217 | MEDIUM | 6.1 | 2019-09-11 | WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled. |
| CVE-2019-16218 | MEDIUM | 6.1 | 2019-09-11 | WordPress before 5.2.3 allows XSS in stored comments. |
| CVE-2019-16219 | MEDIUM | 6.1 | 2019-09-11 | WordPress before 5.2.3 allows XSS in shortcode previews. |
| CVE-2019-16220 | MEDIUM | 6.1 | 2019-09-11 | In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not⦠|
| CVE-2019-16221 | MEDIUM | 6.1 | 2019-09-11 | WordPress before 5.2.3 allows reflected XSS in the dashboard. |
| CVE-2019-16222 | MEDIUM | 6.1 | 2019-09-11 | WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks. |
| CVE-2019-17672 | MEDIUM | 6.1 | 2019-10-17 | WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements. |
| CVE-2020-11027 | MEDIUM | 6.1 | 2020-04-30 | In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user⦠|
| CVE-2021-34656 | MEDIUM | 6.1 | 2021-08-16 | The 2Way VideoCalls and Random Chat - HTML5 Webcam Videochat WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `vws_notice` function found in the ~/inc/requ⦠|
| CVE-2021-25028 | MEDIUM | 6.1 | 2022-01-24 | The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary r⦠|
| CVE-2023-2362 | MEDIUM | 6.1 | 2023-06-12 | The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before⦠|
| CVE-2023-4067 | MEDIUM | 6.1 | 2023-08-02 | The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_date' and 'tab_date_r' parameters in versions up to,⦠|
| CVE-2024-1037 | MEDIUM | 6.1 | 2024-02-07 | The All-In-One Security (AIOS) ā Security and Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and incl⦠|
| CVE-2024-3478 | MEDIUM | 6.1 | 2024-05-02 | The Herd Effects WordPress plugin before 5.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such⦠|
| CVE-2024-11943 | MEDIUM | 6.1 | 2024-12-07 | The ģėķė ģ¤ ź²°ģ ģ¬ķķģ“ ā ģ°ģ»¤ėØøģ¤ ź²°ģ ķė¬ź·øģø plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg() function without appropriate escaping on th⦠|
| CVE-2024-9651 | MEDIUM | 6.1 | 2024-12-09 | The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Sit⦠|
| CVE-2024-12408 | MEDIUM | 6.1 | 2024-12-21 | The WP on AWS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST data in all versions up to, and including, 5.2.1 due to insufficient input sanitizati⦠|
| CVE-2024-12285 | MEDIUM | 6.1 | 2025-01-09 | The SEMA API plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ācatidā parameter in all versions up to, and including, 5.27 due to insufficient input sa⦠|
| CVE-2025-9952 | MEDIUM | 6.1 | 2025-10-04 | The Trinity Audio ā Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'range-date' paramete⦠|
| CVE-2026-2324 | MEDIUM | 6.1 | 2026-03-11 | The LatePoint ā Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.7. T⦠|
| CVE-2025-58674 | MEDIUM | 5.9 | 2025-09-23 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordPress allows Stored XSS. WordPress core security team is aware of the iss⦠|
| CVE-2020-11025 | MEDIUM | 5.8 | 2020-04-30 | In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer allows JavaScript code to be executed. Exploitation requires ⦠|
| CVE-2020-11028 | MEDIUM | 5.8 | 2020-04-30 | In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated disclosure under a specific set of conditions. This has been pat⦠|
| CVE-2020-11029 | MEDIUM | 5.8 | 2020-04-30 | In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited to execute cross-site scripting (XSS) attacks. This has been⦠|
| CVE-2020-4048 | MEDIUM | 5.7 | 2020-06-12 | In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect wh⦠|
| CVE-2022-47599 | MEDIUM | 5.5 | 2023-12-20 | Deserialization of Untrusted Data vulnerability in File Manager by Bit Form Team File Manager ā 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager.This i⦠|
| CVE-2019-16223 | MEDIUM | 5.4 | 2019-09-11 | WordPress before 5.2.3 allows XSS in post previews by authenticated users. |
| CVE-2019-17674 | MEDIUM | 5.4 | 2019-10-17 | WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer. |
| CVE-2020-4046 | MEDIUM | 5.4 | 2020-06-12 | In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfiltered HTML in the block editor⦠|
| CVE-2021-24471 | MEDIUM | 5.4 | 2021-08-16 | The YouTube Embed WordPress plugin before 5.2.2 does not validate, escape or sanitise some of its shortcode attributes, leading to Stored XSS issues by 1. using w, h, controls, cc⦠|
| CVE-2021-24640 | MEDIUM | 5.4 | 2021-09-20 | The WordPress Slider Block Gutenslider plugin before 5.2.0 does not escape the minWidth attribute of a Gutenburg block, which could allow users with a role as low as contributor t⦠|
| CVE-2021-24716 | MEDIUM | 5.4 | 2021-11-01 | The Modern Events Calendar Lite WordPress plugin before 5.22.3 does not properly sanitize or escape values set by users with access to adjust settings withing wp-admin. |
| CVE-2021-44777 | MEDIUM | 5.4 | 2022-01-19 | Cross-Site Request Forgery (CSRF) vulnerabilities leading to single or bulk e-mail entries deletion discovered in Email Tracker WordPress plugin (versions <= 5.2.6). |
| CVE-2022-1051 | MEDIUM | 5.4 | 2022-05-16 | The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanitise and escape the city, phone or profile credentials field⦠|
| CVE-2022-38139 | MEDIUM | 5.4 | 2022-09-13 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in RD Station plugin <= 5.2.0 at WordPress. |
| CVE-2024-1809 | MEDIUM | 5.4 | 2024-05-02 | The Analytify ā Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch⦠|
| CVE-2019-17671 | MEDIUM | 5.3 | 2019-10-17 | In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled. |
| CVE-2024-1584 | MEDIUM | 5.3 | 2024-05-02 | The Analytify ā Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil⦠|
| CVE-2024-9940 | MEDIUM | 5.3 | 2024-10-17 | The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.2.45. This is due to the plugin not properly neutralizing H⦠|
| CVE-2024-12601 | MEDIUM | 5.3 | 2024-12-17 | The Calculated Fields Form plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 5.2.63. This is due to unlimited height and width paramete⦠|
| CVE-2024-13666 | MEDIUM | 5.3 | 2025-03-22 | The Fluent Forms ā Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and inc⦠|
| CVE-2025-9984 | MEDIUM | 5.3 | 2025-09-26 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the fifu_api_debug_posts() function in al⦠|
| CVE-2025-9985 | MEDIUM | 5.3 | 2025-09-26 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.7 through publicly exposed log fi⦠|
| CVE-2025-9196 | MEDIUM | 5.3 | 2025-10-11 | The Trinity Audio ā Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in⦠|
| CVE-2026-1537 | MEDIUM | 5.3 | 2026-02-12 | The LatePoint ā Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the load⦠|
| CVE-2008-4107 | MEDIUM | 5.1 | 2008-09-18 | The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows attackers to leverage exposures in products that rely on t⦠|
| CVE-2024-32111 | MEDIUM | 5.0 | 2024-06-25 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic WordPress allows Relative Path Traversal.This issue affects WordPress: f⦠|
| CVE-2025-8009 | MEDIUM | 4.9 | 2025-07-24 | The Security Ninja ā WordPress Security Plugin & Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.242 via the 'get_file_s⦠|
| CVE-2025-10036 | MEDIUM | 4.9 | 2025-09-26 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to SQL Injection via the get_all_urls() function in all versions up to, and including, 5.2.7 due to insuffici⦠|
| CVE-2025-10037 | MEDIUM | 4.9 | 2025-09-26 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to SQL Injection via the get_posts_with_internal_featured_image() function in all versions up to, and includi⦠|
| CVE-2021-24687 | MEDIUM | 4.8 | 2021-10-04 | The Modern Events Calendar Lite WordPress plugin before 5.22.2 does not escape some of its settings before outputting them in attributes, allowing high privilege users to perform ⦠|
| CVE-2022-0663 | MEDIUM | 4.8 | 2022-06-20 | The Print, PDF, Email by PrintFriendly WordPress plugin before 5.2.3 does not sanitise and escape the Custom Button Text settings, which could allow high privilege users such as a⦠|
| CVE-2022-2407 | MEDIUM | 4.8 | 2022-08-22 | The WP phpMyAdmin WordPress plugin before 5.2.0.4 does not escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting⦠|
| CVE-2022-3936 | MEDIUM | 4.8 | 2023-01-02 | The Team Members WordPress plugin before 5.2.1 does not sanitize and escapes some of its settings, which could allow high-privilege users such as editors to perform Stored Cross-S⦠|
| CVE-2023-2711 | MEDIUM | 4.8 | 2023-06-27 | The Ultimate Product Catalog WordPress plugin before 5.2.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Store⦠|
| CVE-2023-4022 | MEDIUM | 4.8 | 2023-09-11 | The Herd Effects WordPress plugin before 5.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site⦠|
| CVE-2024-6724 | MEDIUM | 4.8 | 2024-08-13 | The Generate Images WordPress plugin before 5.2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-⦠|
| CVE-2024-13381 | MEDIUM | 4.8 | 2025-05-01 | The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored⦠|
| CVE-2024-13382 | MEDIUM | 4.8 | 2025-05-15 | The Calculated Fields Form WordPress plugin before 5.2.64 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored⦠|
| CVE-2024-12203 | MEDIUM | 4.4 | 2025-01-17 | The RSS Icon Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ālink_colorā parameter in all versions up to, and including, 5.2 due to insufficient ⦠|
| CVE-2022-1349 | MEDIUM | 4.3 | 2022-05-16 | The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the value passed to the image_id parameter of the ⦠|
| CVE-2022-1425 | MEDIUM | 4.3 | 2022-05-16 | The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the message_id of the wpqa_message_view ajax actio⦠|
| CVE-2022-1421 | MEDIUM | 4.3 | 2022-06-08 | The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in admin change arbitrary 's settings including payment methods ⦠|
| CVE-2023-4318 | MEDIUM | 4.3 | 2023-09-11 | The Herd Effects WordPress plugin before 5.2.4 does not have CSRF when deleting its items, which could allow attackers to make logged in admins delete arbitrary effects via a CSRF⦠|
| CVE-2023-39999 | MEDIUM | 4.3 | 2023-10-13 | Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 thr⦠|
| CVE-2024-13317 | MEDIUM | 4.3 | 2025-01-18 | The ShipWorks Connector for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.5. This is due to missing or inc⦠|
| CVE-2025-58246 | MEDIUM | 4.3 | 2025-09-23 | Insertion of Sensitive Information Into Sent Data vulnerability in WordPress allows Retrieve Embedded Sensitive Data. The WordPress Core security team is aware of the issue and is⦠|
| CVE-2025-9886 | MEDIUM | 4.3 | 2025-10-04 | The Trinity Audio ā Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ⦠|
| CVE-2025-12953 | MEDIUM | 4.3 | 2025-11-11 | The Classified Listing ā AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ⦠|
| CVE-2025-14873 | MEDIUM | 4.3 | 2026-02-14 | The LatePoint ā Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.5. T⦠|
| CVE-2026-2306 | MEDIUM | 4.3 | 2026-05-06 | The Ninja Tables ā Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation due to missing authorization checks on the `createFluentCartT⦠|
| CVE-2025-4202 | MEDIUM | 4.3 | 2026-05-16 | The Multicollab: Content Team Collaboration and Editorial Workflow plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the⦠|
| CVE-2020-4050 | LOW | 3.5 | 2020-06-12 | In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plu⦠|
| CVE-2024-12273 | LOW | 3.5 | 2025-04-29 | The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored⦠|
| CVE-2020-4049 | LOW | 2.4 | 2020-06-12 | In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes p⦠|
Plain English Ā· Fix recommendations Ā· Instant PDF & HTML download
Scan your site in 30 seconds. Used by 500+ web agencies.
WordPress 5.2 is dangerously outdated with 9 critical vulnerabilities that hackers actively exploit. Staying on this version puts your business, customer data, and reputation at serious risk. The good news is that updating takes minutes and immediately closes the majority of these security holes.
Don't wait for a breach to happen. Use SiteRecipe.com's free security scanning tool to instantly identify all vulnerabilities on your WordPress site, get personalized fix recommendations, and monitor your security continuously. Our platform makes it simple to stay ahead of threats so you can focus on growing your business instead of worrying about security.
Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.