Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 6.9
Security Advisory

WordPress 6.9: 28 Critical Vulnerabilities & Security Guide

📅 June 07, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
1,021 websites still running wordpress 6.9  → View full list
28
Total
5
Critical
10
High
13
Medium

WordPress 6.9 has been flagged with 28 security vulnerabilities—including 5 critical flaws that could give attackers complete control of your website. Over 1,021 websites are currently running this vulnerable version, making them prime targets for hackers. In this guide, we'll show you exactly what these vulnerabilities are, how to check if your site is affected, and the steps to secure your WordPress installation immediately.

The most dangerous CVEs affect file uploads, SQL injection, and account takeover capabilities. Without urgent patching, attackers could execute malicious code on your server, steal customer data, or hijack administrator accounts. If you're running WordPress 6.9, this is not a guide you can afford to skip.

What is Wordpress 6.9?

WordPress 6.9 is a version of the world's most popular website platform, used by millions of websites globally. Like all software, WordPress regularly receives updates that add new features and fix security problems. Version 6.9 was released to improve functionality, but security researchers discovered serious flaws that weren't properly addressed before release.

These vulnerabilities primarily exist in plugins (add-ons that extend WordPress functionality) rather than WordPress core itself. Plugins like File Manager, WPCargo, and Block Bad Bots contain code that doesn't properly validate user input, leaving doors wide open for attackers. Even though WordPress 6.9 is not the latest version, thousands of site owners haven't updated, leaving themselves dangerously exposed.

Key Vulnerabilities in Wordpress 6.9

28 CVEs found. The most critical are explained below.

CRITICAL CVE-2020-25213 10.0/10 · CVSS v3.1 ⏱ Immediate
File Manager Plugin Allows Hackers to Upload Malicious Code

The File Manager plugin has a security flaw that lets attackers upload and run dangerous code on your website. This happens because the plugin doesn't properly protect a file that should never be executable. Hackers can exploit this to take complete control of your site.

Impact: An attacker could gain full control of your website, steal customer data, install malware, or use your site to attack other websites.

↗ View on NVD
CRITICAL CVE-2021-25003 9.8/10 · CVSS v3.1 ⏱ Immediate
WPCargo Plugin Allows Unauthorized File Creation and Code Execution

The WPCargo Track & Trace plugin contains a vulnerability that lets anyone create malicious PHP files on your server without needing to log in. Once uploaded, these files can be executed to run harmful commands on your website.

Impact: Attackers could completely compromise your website, access sensitive customer information, modify site content, or use your server for illegal activities.

↗ View on NVD
CRITICAL CVE-2022-0949 9.8/10 · CVSS v3.1 ⏱ Immediate
Bot Protection Plugin Has Database Injection Vulnerability

The Block Bad Bots plugin doesn't properly validate user input, which allows attackers to inject harmful SQL commands into your database. Visitors don't even need to be logged in to exploit this weakness.

Impact: Hackers could read, modify, or delete your database contents, including customer information, posts, and user accounts.

↗ View on NVD
CRITICAL CVE-2023-0600 9.8/10 · CVSS v3.1 ⏱ Immediate
Traffic Statistics Plugin Vulnerable to Database Attacks

The WP Visitor Statistics plugin doesn't properly filter user input before using it in database queries. This allows anyone visiting your site to inject malicious SQL commands without logging in.

Impact: Attackers could extract sensitive data from your database, modify website content, or cause your website to malfunction completely.

↗ View on NVD
CRITICAL CVE-2024-11284 9.8/10 · CVSS v3.1 ⏱ Immediate
Job Hunt Plugin Allows Account Takeover Without Verification

The WP JobHunt plugin doesn't properly verify user identity when someone tries to change a password. This means an attacker can reset any user's password, including admin accounts, without providing the correct credentials.

Impact: Attackers could take over user accounts, particularly admin accounts, and gain full control of your website and all associated data.

↗ View on NVD
HIGH CVE-2022-3246 8.8/10 · CVSS v3.1 ⏱ Within 7 days
Social Media Plugin Has Database Injection Vulnerability

The Blog2Social plugin doesn't properly protect user input in database queries. While this requires a logged-in user to exploit, even low-level users like subscribers can use this to inject malicious SQL commands.

Impact: Logged-in users could extract sensitive data from your database or modify content without proper authorization.

↗ View on NVD

Additional Vulnerabilities (22 more)

Showing first 10 of 22. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2024-10729 HIGH 8.8 2024-11-26 The Booking & Appointment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_google_cale…
CVE-2024-12035 HIGH 8.8 2025-03-07 The CS Framework plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the cs_widget_file_delete() function in all versions up …
CVE-2025-66428 HIGH 8.8 2026-01-22 An issue with WordPress directory names in WebPros WordPress Toolkit before 6.9.1 allows privilege escalation.
CVE-2024-32692 HIGH 8.2 2024-05-17 Missing Authorization vulnerability in QuanticaLabs Chauffeur Taxi Booking System for WordPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects …
CVE-2024-13777 HIGH 8.1 2025-03-05 The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.91 via deserializatio…
CVE-2024-13776 HIGH 8.1 2025-04-05 The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a mi…
CVE-2018-7433 HIGH 7.5 2018-03-02 The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.
CVE-2024-12036 HIGH 7.5 2025-03-07 The CS Framework plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.9 via the get_widget_settings_json() function. This makes it pos…
CVE-2025-3431 HIGH 7.5 2025-04-08 The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.91 via the 'dzsap_down…
CVE-2021-24770 MEDIUM 6.5 2021-11-01 The Stylish Price List WordPress plugin before 6.9.1 does not perform capability checks in its spl_upload_ser_img AJAX action (available to authenticated users), which could allow…
Full Report Available

All 28 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 6.9?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 6.9's 28 vulnerabilities—especially the 5 critical CVEs—represent a genuine threat to your website's security. Account takeovers, file uploads, SQL injection attacks, and remote code execution are all possible if you delay patching. The good news is that updating WordPress and your plugins is straightforward and can be completed in minutes.

Don't leave your website vulnerable another day. Use SiteRecipe.com to continuously monitor your WordPress installation, plugins, and themes for new vulnerabilities. Our platform automatically alerts you to security risks and provides step-by-step guidance to fix them, so you can focus on running your business instead of worrying about hackers. Start your free security scan today and get peace of mind knowing your site is protected.

Frequently Asked Questions

Is WordPress 6.9 dangerous to use?
Yes, especially if you have the vulnerable plugins installed. While WordPress 6.9 core itself is relatively secure, the critical vulnerabilities exist in popular plugins. You should update to the latest WordPress version and patch all plugins immediately to eliminate the risk.
Can hackers exploit these CVEs on my site right now?
It depends on which plugins you're using. If you have File Manager, WPCargo, Block Bad Bots, WP Visitor Statistics, WP JobHunt, or Blog2Social installed, yes—attackers can exploit them without even needing to log in. This is why immediate action is critical.
Will updating WordPress break my website?
Updating WordPress is very safe, especially if you follow best practices. Always backup your site before updating, and test the update on a staging environment if possible. Most updates are fully backward compatible and won't break existing functionality or plugins.
How often should I check for WordPress vulnerabilities?
Ideally, you should check weekly or enable automatic updates. Security threats emerge constantly, and hackers actively target outdated installations. Using SiteRecipe.com gives you real-time monitoring so you never miss a critical vulnerability.
What if I can't update a vulnerable plugin?
If a plugin isn't being maintained or updated by its developer, you should deactivate and remove it immediately. The security risk outweighs the functionality it provides. Look for alternative, actively maintained plugins that offer the same features.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 07, 2026 · SiteRecipe.com