Home Plans Products
Tools
Technology Trends Keyword Lists Browser Extensions
Features
Lead Generation Market Analysis Sales Intelligence
Resources
FAQ About Contact Blog
Account
Login Sign up
Home / Blog / wordpress 7.3
Security Advisory

WordPress 7.3: 47 CVEs Found – Critical Security Update

📅 June 08, 2026 ·⏱ 5 min read ·🔒 SiteRecipe Security Team
1,021 websites still running wordpress 7.3  → View full list
47
Total
4
Critical
8
High
30
Medium
5
Low

WordPress 7.3 is currently affected by 47 documented security vulnerabilities, including 4 critical CVEs that put your website at immediate risk. With over 1,021 websites still running this outdated version, cybercriminals are actively targeting these known weaknesses. SQL injection attacks, authentication bypasses, and privilege escalation exploits are actively being leveraged against unpatched installations.

This comprehensive guide will help you identify if your site is vulnerable, understand the specific threats you're facing, and implement the necessary security patches. Taking immediate action is not optional—it's essential to protect your data, your users, and your business reputation.

We'll walk you through the exact steps to secure your WordPress installation and prevent the exploitation of these dangerous vulnerabilities.

What is Wordpress 7.3?

WordPress 7.3 is a version of WordPress, the content management system powering over 43% of all websites on the internet. It allows you to create, manage, and publish content without requiring advanced coding knowledge. Think of it as the foundation of your website—it manages everything from posts and pages to user accounts and plugins that add extra functionality.

Like all software, WordPress receives regular updates that fix security problems discovered by researchers. Version 7.3 was released several years ago, and since then, developers have discovered numerous security flaws in both WordPress itself and the popular plugins used with it. Using an outdated version is like leaving your front door unlocked—attackers actively search for these known weaknesses to break in.

Key Vulnerabilities in Wordpress 7.3

47 CVEs found. The most critical are explained below.

CRITICAL CVE-2019-13573 9.8/10 · CVSS v3.1 ⏱ Immediate
FV Flowplayer Video Player - Database Attack Vulnerability

The FV Flowplayer Video Player plugin (before version 7.3.19.727) has a serious flaw that lets hackers directly access and manipulate your website's database. This is like leaving your filing cabinets unlocked with a map to where everything is stored.

Impact: Attackers could steal all your website data, modify customer information, delete content, or inject malicious code into your site.

↗ View on NVD
CRITICAL CVE-2019-14801 9.8/10 · CVSS v3.0 ⏱ Immediate
FV Flowplayer Video Player - Email List Breach Risk

An older version of the FV Flowplayer plugin (before 7.3.15.727) has a vulnerability specifically targeting email subscription data. Hackers can exploit this to access your email subscriber list.

Impact: Your email subscriber database could be stolen, compromised, or deleted, affecting your ability to communicate with customers.

↗ View on NVD
CRITICAL CVE-2020-36832 9.8/10 · CVSS v3.1 ⏱ Immediate
Ultimate Membership Pro - Admin Login Bypass

The Ultimate Membership Pro plugin (versions 7.3 to 8.6) allows anyone to log in as any user, including your admin account, without needing a password. It's like someone can walk into your office and sit at your desk.

Impact: Attackers gain full control of your website, can delete content, steal data, modify settings, or lock you out of your own site.

↗ View on NVD
CRITICAL CVE-2026-5076 9.8/10 · CVSS v3.1 ⏱ Immediate
ARMember Premium - Insecure Password Reset Flaw

The ARMember Premium plugin (up to version 7.3.1) stores password reset keys in plain text, making them visible to anyone with database access. This is like writing passwords on a sticky note attached to your monitor.

Impact: Hackers can use exposed password reset keys to take over user accounts, including admin accounts, without your knowledge.

↗ View on NVD
HIGH CVE-2025-8899 8.8/10 · CVSS v3.1 ⏱ Within 7 days
Paid Videochat Plugin - User Permission Escalation

The Paid Videochat Turnkey Site plugin (up to version 7.3.20) doesn't properly restrict what user roles can be assigned during registration. Someone could register as an administrator instead of a regular user.

Impact: Unauthorized users could gain admin privileges, giving them control over your entire website and all its settings.

↗ View on NVD
HIGH CVE-2024-10855 8.1/10 · CVSS v3.1 ⏱ Within 7 days
Sirv Image Optimizer - File Upload Security Gap

The Sirv image optimizer plugin (up to version 7.3.20) doesn't properly validate files being uploaded, allowing attackers to upload malicious files or use the feature to crash your site.

Impact: Your site could go down (denial of service), or malicious files could be uploaded and executed on your server.

↗ View on NVD

Additional Vulnerabilities (41 more)

Showing first 10 of 41. View all on NVD ↗

CVE IDSeverityScore PublishedDescription
CVE-2021-36898 HIGH 7.5 2022-10-28 Auth. SQL Injection (SQLi) vulnerability in Quiz And Survey Master plugin <= 7.3.4 on WordPress.
CVE-2024-12330 HIGH 7.5 2025-01-09 The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi…
CVE-2024-13496 HIGH 7.5 2025-01-22 The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ pa…
CVE-2026-5073 HIGH 7.5 2026-06-02 The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'arm_directory_paging_action' AJAX action in all versions up to, and incl…
CVE-2024-1793 HIGH 7.2 2024-03-13 The AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth plugin for WordPress is vulnerable to SQL Injection via the 'post_id…
CVE-2025-13145 HIGH 7.2 2025-11-19 The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.33.1. This is due to des…
CVE-2008-0560 MEDIUM 6.8 2008-02-04 PHP remote file inclusion vulnerability in cforms-css.php in Oliver Seidel cforms (contactforms), a Wordpress plugin, allows remote attackers to execute arbitrary PHP code via a U…
CVE-2022-41652 MEDIUM 6.5 2022-11-18 Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.
CVE-2024-3934 MEDIUM 6.5 2024-07-20 The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to Path Traversal in versions 7.3.0 to 7.5.1 via the mercadopagoDownloadLog function. This makes it po…
CVE-2026-1317 MEDIUM 6.5 2026-02-18 The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 7.37. This is due to insufficient…
Full Report Available

All 47 CVEs with AI explanations + fix guide

Plain English · Fix recommendations · Instant PDF & HTML download

⬇ Get Full Report
PDF + HTML · Instant download

Is your website running Wordpress 7.3?

Scan your site in 30 seconds. Used by 500+ web agencies.

How to Check If Your Website Is Affected

How to Fix These Vulnerabilities

Conclusion

WordPress 7.3 contains 47 security vulnerabilities that hackers are actively exploiting right now. The 4 critical CVEs alone can lead to complete website compromise, user data theft, and loss of administrator access. Delaying this update puts your business at severe risk, and compliance requirements in many industries mandate prompt patching of known vulnerabilities.

Don't leave your website vulnerable another day. SiteRecipe.com provides automated security scanning and vulnerability management tools that identify outdated versions, track CVEs affecting your specific plugins, and alert you to threats in real-time. Visit SiteRecipe.com today to scan your WordPress installation for free and get a detailed security report with step-by-step remediation guidance tailored to your site.

Frequently Asked Questions

Will updating WordPress 7.3 delete my content or break my website?
No. Updating WordPress preserves all your content, posts, pages, and user data. However, outdated plugins may occasionally have compatibility issues with newer WordPress versions. That's why creating a backup first is critical—it lets you restore your site if any plugin conflicts occur, though this is rare with reputable plugins.
How long does it take to update WordPress from 7.3 to the latest version?
The update itself typically takes 2-5 minutes to download and install. However, you should allow 15-30 minutes total when including backup creation, testing afterward, and verifying that all your site features work correctly. Choose a time when traffic is lowest to minimize any potential disruption.
Are the SQL injection vulnerabilities in WordPress 7.3 being actively exploited?
Yes. CVE-2019-13573 and CVE-2014801 are actively exploited in the wild because they allow attackers to steal data directly from your database without needing valid login credentials. If you run FV Flowplayer or Ultimate Membership Pro plugins on version 7.3, your risk is exceptionally high and demands immediate patching.
What happens if my site gets hacked through these vulnerabilities?
Attackers could steal customer data, inject malware, send spam from your server, modify your content, lock you out of your own website, or use your site to attack other websites. Recovery can cost thousands of dollars in cleanup fees and cause severe damage to your reputation and search engine rankings.
Can I skip updating and just disable vulnerable plugins instead?
Not safely. Many of these vulnerabilities affect core WordPress functionality and popular plugins. Additionally, new vulnerabilities are discovered regularly—running outdated software is inherently risky. Regular updates are the only reliable security practice for WordPress sites.

Generate white-label reports for your clients

Web agencies use SiteRecipe to produce branded PDF security reports in 30 seconds.

DISCLAIMER: This report is based on publicly available CVE data from the National Vulnerability Database (NVD) maintained by NIST. Detection of a technology version does not confirm active exploitation on any specific website. For informational purposes only. SiteRecipe is not responsible for actions taken based on this report. Always consult a qualified security professional.

Source: nvd.nist.gov · Published: June 08, 2026 · SiteRecipe.com