Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 7.0
Security Advisory

WordPress 7.0 Security: 43 CVEs Found - Update Now

📅 June 08, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
1,021 websites still running wordpress 7.0  → View full list
43
Total
6
Critical
15
High
22
Medium

WordPress 7.0 is currently running on over 1,000 websites, but security researchers have discovered a critical security crisis affecting this version. A total of 43 vulnerabilities have been identified, including 6 critical-severity flaws that could allow attackers to take complete control of your website. These aren't theoretical threats—they're actively exploited vulnerabilities that put your data, visitors, and business at immediate risk.

The vulnerabilities span across popular WordPress plugins including wpDiscuz, Quiz and Survey Master, WP User, Site Reviews, and Events Calendar Pro. Many of these flaws allow unauthenticated attackers to execute malicious code, delete critical files, bypass security controls, and manipulate your site without any authorization. If your website is running WordPress 7.0, you need to take action immediately to protect yourself.

What is Wordpress 7.0?

WordPress 7.0 is a content management system that powers millions of websites worldwide. It's used by bloggers, small businesses, e-commerce stores, and large enterprises to create, manage, and publish web content without requiring advanced coding knowledge. WordPress allows users to build websites through themes, plugins, and a user-friendly dashboard interface.

Like all software, WordPress relies on plugins and extensions to add functionality to core features. While these plugins provide valuable tools—from contact forms to event management to user registration—they can also introduce security vulnerabilities if not properly maintained or coded. WordPress 7.0 specifically has multiple plugin-related vulnerabilities that create serious security gaps for website owners.

Key Vulnerabilities in Wordpress 7.0

43 CVEs found. The most critical are explained below.

CRITICAL CVE-2020-24186 10.0/10 · CVSS v3.1 ⏱ Immediate
wpDiscuz Plugin Allows Hackers to Upload Malicious Files

The wpDiscuz plugin (versions 7.0-7.0.4) has a security hole that lets anyone upload files to your website without logging in. Attackers can upload dangerous files like PHP scripts that give them complete control of your site.

Impact: A hacker could take over your entire WordPress site, steal customer data, install malware, or use your site to attack others.

↗ View on NVD
CRITICAL CVE-2020-35949 10.0/10 · CVSS v3.1 ⏱ Immediate
Quiz and Survey Master Plugin Allows File Uploads and Takeover

The Quiz and Survey Master plugin (before 7.0.1) allows anyone to upload files through quiz questions without proper security checks. Hackers can upload malicious code that runs on your server.

Impact: An attacker gains full control of your website, can steal all your data, modify pages, or shut down your site completely.

↗ View on NVD
CRITICAL CVE-2020-35951 9.9/10 · CVSS v3.1 ⏱ Immediate
Quiz and Survey Master Plugin Allows File Deletion

The same Quiz and Survey Master plugin also lets attackers delete critical files from your website, including the main WordPress configuration file. This can completely disable your site.

Impact: Your website goes offline and becomes inaccessible. An attacker could then reinstall WordPress under their control, gaining permanent access to your site.

↗ View on NVD
CRITICAL CVE-2022-4049 9.8/10 · CVSS v3.1 ⏱ Immediate
WP User Plugin Vulnerable to Database Attack

The WP User plugin (through version 7.0) doesn't properly protect database queries, allowing hackers to inject malicious code. Anyone can exploit this without needing a login.

Impact: Attackers can access, modify, or delete your database containing customer information, posts, and sensitive business data.

↗ View on NVD
CRITICAL CVE-2024-3050 9.1/10 · CVSS v3.1 ⏱ Within 7 days
Site Reviews Plugin IP Detection Can Be Fooled

The Site Reviews plugin (before 7.0.0) incorrectly identifies visitor IP addresses, making it easy for attackers to trick security systems. If you use IP-based blocking to protect your site, this bypasses it.

Impact: Attackers can circumvent your IP-based security filters and gain unauthorized access to restricted areas of your site.

↗ View on NVD
CRITICAL CVE-2024-8016 9.1/10 · CVSS v3.1 ⏱ Within 30 days
Events Calendar Pro Plugin Vulnerable to Advanced Attack

The Events Calendar Pro plugin (through 7.0.2) has a flaw in how it processes widget data. An admin account with elevated permissions could be tricked into executing malicious code.

Impact: Someone with administrative access could be manipulated into running code that compromises your site or gives an attacker elevated control.

↗ View on NVD

Additional Vulnerabilities (37 more)

Showing first 10 of 37. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2023-1273 HIGH 8.8 2023-07-04 The ND Shortcodes WordPress plugin before 7.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authentica…
CVE-2024-0786 HIGH 8.8 2024-02-28 The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the ee_syncP…
CVE-2024-1203 HIGH 8.8 2024-03-13 The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'valueData' paramet…
CVE-2025-11923 HIGH 8.8 2025-11-13 The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to privilege escalation. This is due to the plugin not properly validating a use…
CVE-2026-1750 HIGH 8.8 2026-02-15 The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.0.7. This is due to a missing ca…
CVE-2026-6692 HIGH 8.8 2026-05-07 The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_get_media_url' and '_check_file_path' function. This is due…
CVE-2026-7654 HIGH 8.8 2026-06-05 The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in versions up to and including 7.0.18. This is due to the use of `un…
CVE-2024-13440 HIGH 8.2 2025-02-09 The Super Store Finder plugin for WordPress is vulnerable to SQL Injection via the ‘ssf_wp_user_name’ parameter in all versions up to, and including, 7.0 due to insufficient escap…
CVE-2014-2316 HIGH 7.5 2014-03-09 SQL injection vulnerability in se_search_default in the Search Everything plugin before 7.0.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the s par…
CVE-2021-24981 HIGH 7.5 2021-12-21 The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins…
Full Report Available

All 43 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 7.0?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 7.0 users face an urgent security situation with 6 critical vulnerabilities that could lead to complete site compromise. The combination of remote code execution, arbitrary file uploads, SQL injection, and object injection vulnerabilities creates multiple pathways for attackers to infiltrate your website. Delaying updates isn't an option—these are actively exploited vulnerabilities that criminals use to steal data, inject malware, and hijack websites for their own purposes.

Don't leave your website vulnerable to these threats. Use SiteRecipe.com's comprehensive security scanner to identify which vulnerabilities affect your site, verify that all updates are applied, and confirm that no previous compromises have occurred. Our tool checks for all 43 known vulnerabilities in WordPress 7.0 and provides detailed remediation guidance specific to your setup. Take control of your security today—scan your site with SiteRecipe.com for free and protect your business from exploitation.

Frequently Asked Questions

How serious are the WordPress 7.0 vulnerabilities?
Very serious. The 6 critical vulnerabilities can allow attackers to upload malicious code, delete essential files like wp-config.php, manipulate IP blocking, and gain full administrative access to your site. These aren't minor issues—they can result in complete site takeover and data theft.
Will updating WordPress 7.0 fix all these vulnerabilities?
Updating WordPress core will fix WordPress-specific issues, but most of these vulnerabilities are in plugins like wpDiscuz, Quiz and Survey Master, and Events Calendar Pro. You must update both WordPress and all your plugins to patch all 43 vulnerabilities.
Can I check if my site has been hacked due to these vulnerabilities?
Yes. SiteRecipe.com's security scanner will identify if these vulnerabilities exist on your site and detect signs of compromise. However, you should also scan for malware, review your access logs, and change all passwords immediately after updating to be completely safe.
What should I do if I can't update a plugin with vulnerabilities?
If a plugin has critical vulnerabilities and hasn't been updated, you should deactivate and delete it immediately, then find a secure alternative that's actively maintained. Running vulnerable plugins is riskier than losing functionality.
How did WordPress 7.0 get so many vulnerabilities?
WordPress 7.0 itself is stable, but the vulnerabilities primarily exist in third-party plugins that extend WordPress functionality. Plugin developers have varying security practices, and some vulnerabilities take time to discover and patch, which is why keeping everything updated is critical.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 08, 2026 · SiteRecipe.com