Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 5.3
Security Advisory

WordPress 5.3: 108 Critical Vulnerabilities You Must Fix Now

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
12 websites still running wordpress 5.3  → View full list
108
Total
5
Critical
29
High
74
Medium

WordPress 5.3 contains a serious security issue: 108 documented vulnerabilities, including 5 critical flaws that could allow hackers to take over your website completely. If you're still running this version, your site is at significant risk. The good news? You can fix this problem quickly by understanding what vulnerabilities exist and how to patch them.

This guide walks you through identifying if your WordPress installation is vulnerable, understanding the specific threats, and implementing the fixes that will protect your website and your visitors' data. Even if you think you're safe, reading this could save you from a costly security breach.

What is Wordpress 5.3?

WordPress 5.3 was released in November 2019 as a major update to the popular website platform. Like all software, it received security patches after release, but this particular version contains numerous unpatched vulnerabilities that make it dangerous to use today. These aren't theoretical threats—hackers actively exploit these known weaknesses to gain access to websites, steal data, and deploy malware.

The vulnerabilities in WordPress 5.3 span multiple categories: some allow attackers to upload malicious files, others enable them to bypass security protections, and several create SQL injection opportunities that expose your entire database. The 5 critical vulnerabilities are especially dangerous because they require no special access or authentication—any attacker on the internet can exploit them.

Key Vulnerabilities in Wordpress 5.3

108 CVEs found. The most critical are explained below.

CRITICAL CVE-2020-35489 10.0/10 · CVSS v3.1 ⏱ Immediate
Contact Form 7 Plugin - Hackers Can Upload Malicious Files

The Contact Form 7 plugin has a serious flaw that allows attackers to upload harmful files to your website by tricking the upload system with specially crafted filenames. Once uploaded, these files can give hackers complete control over your entire WordPress site.

Impact: Hackers could upload malware, steal customer data, send spam emails from your domain, or completely take over your website. Your site could be used to attack other websites.

↗ View on NVD
CRITICAL CVE-2019-20041 9.8/10 · CVSS v3.1 ⏱ Immediate
WordPress Core - Security Filters Can Be Bypassed

WordPress has built-in protections to block dangerous code in comments and forms. This vulnerability allows attackers to sneak malicious JavaScript code past these protections using a trick with HTML formatting.

Impact: Hackers could inject malicious code that steals visitor information, hijacks user accounts, or spreads malware through your website.

↗ View on NVD
CRITICAL CVE-2020-13640 9.8/10 · CVSS v3.1 ⏱ Immediate
wpDiscuz Plugin - Database Can Be Hacked

The wpDiscuz commenting plugin contains a vulnerability that allows attackers to directly access and manipulate your website's database through the comments section. They can read, modify, or delete any information stored in your database.

Impact: Complete exposure of your database including customer information, passwords, and all website content. Attackers could modify or delete critical data.

↗ View on NVD
CRITICAL CVE-2024-13645 9.8/10 · CVSS v3.1 ⏱ Immediate
tagDiv Composer Plugin - Unauthorized System Access

The tagDiv Composer plugin allows attackers to manipulate WordPress system components without needing a login. This creates a doorway for unauthorized access to your website's core functions.

Impact: Attackers could execute malicious actions on your website without authentication, potentially leading to data theft or site compromise.

↗ View on NVD
CRITICAL CVE-2019-1010257 9.1/10 · CVSS v3.1 ⏱ Immediate
Article2PDF Plugin - Unauthorized File Access

The article2pdf plugin has a flaw that allows attackers to access any files on your web server by manipulating the file path. They can download sensitive files like configuration files containing passwords and database credentials.

Impact: Exposure of critical files including database passwords, configuration files, and other sensitive information that could lead to complete site compromise.

↗ View on NVD
HIGH CVE-2018-6467 8.8/10 · CVSS v3.0 ⏱ Within 7 days
flickrRSS Plugin - Unauthorized Settings Changes

The flickrRSS plugin allows attackers to trick site administrators into changing website settings by clicking malicious links. The plugin doesn't properly verify that setting change requests come from authorized users.

Impact: Attackers could modify your website's critical settings, potentially redirecting traffic, inserting ads, or changing your site's functionality without your knowledge.

↗ View on NVD

Additional Vulnerabilities (102 more)

Showing first 10 of 102. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2021-42362 HIGH 8.8 2021-11-17 The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes i…
CVE-2022-0439 HIGH 8.8 2022-03-07 The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it …
CVE-2023-0940 HIGH 8.8 2023-03-20 The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement proper authorization. This allows a user with low priv…
CVE-2021-4337 HIGH 8.8 2023-06-07 Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability check on the wp_ajax_svx_ajax_factory function in various v…
CVE-2023-0579 HIGH 8.8 2023-08-16 The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated us…
CVE-2023-6979 HIGH 8.8 2024-01-11 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ivole_import_upload_csv AJAX action in…
CVE-2024-1990 HIGH 8.8 2024-04-09 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to blind SQL Injection via the ‘id’ parameter of t…
CVE-2024-1991 HIGH 8.8 2024-04-09 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to privilege escalation due to a missing capabilit…
CVE-2024-6756 HIGH 8.8 2024-07-24 The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpw_auto_poster_get_image_path' function in all ver…
CVE-2025-2158 HIGH 8.8 2025-05-10 The WordPress Review Plugin: The Ultimate Solution for Building a Review Website plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5…
Full Report Available

All 108 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 5.3?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 5.3 is no longer safe to use in 2024. With 108 documented vulnerabilities and active exploitation by cybercriminals, staying on this version puts your business at serious risk. The update process takes just minutes and immediately eliminates the critical threats targeting your site. Don't wait for a breach to happen—update today and sleep soundly knowing your WordPress installation is secure.

SiteRecipe.com's security monitoring tools automatically scan your WordPress version, detect vulnerabilities, and alert you to necessary updates before hackers find your site. Visit SiteRecipe.com now to run a free security audit of your WordPress installation and get a personalized action plan to eliminate all 108 vulnerabilities in minutes.

Frequently Asked Questions

What happens if I don't update from WordPress 5.3?
Hackers can exploit critical vulnerabilities to upload malicious files, steal your database, inject malware into your site, or take complete control of your WordPress admin. Your visitors' data, payment information, and personal details are all at risk. A security breach is expensive to fix and damages your reputation.
Will updating WordPress break my website?
Major WordPress updates rarely break well-maintained sites. The key is having a recent backup before you update, which is standard practice. If issues do occur, you can restore from backup. Most sites update seamlessly, and the security benefits far outweigh the minimal risk.
Is WordPress 5.3 still supported with security patches?
No. WordPress 5.3 reached end-of-life years ago and receives no security updates. Only the latest WordPress version and the two previous major versions receive ongoing security support. If you're on 5.3, you must upgrade to a currently supported version like 6.4 or 6.5.
How do I know if attackers have already compromised my site?
Run a professional security scan using tools like Wordfence, Sucuri, or SiteRecipe.com. These scan for backdoors, malware, and unauthorized admin accounts. If your site was vulnerable for months, a breach is possible. A thorough scan will detect most threats, though some sophisticated attacks require expert forensic analysis.
Can I stay on WordPress 5.3 if I disable all plugins?
No. Critical vulnerabilities exist in WordPress core itself, not just plugins. Even with plugins disabled, attackers can exploit CVE-2019-20041 and other core vulnerabilities to compromise your site. You must upgrade the WordPress version itself.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com