904-447-0750
904-447-0750
Breaking News: Core Vulnerabilities Affect Millions of WordPress Websites
SEO / AEO / GEO
Breaking News: Core Vulnerabilities Affect Millions of WordPress Websites
Peter RoeslerWritten ByPeter Roesler  ·  January 2022  ·  5 min read

Most business owners are well aware of just how important a functional and secure website is. If your website is one of the 455 million domains that was built using the open-source software known as WordPress, you need to be aware of recent core vulnerabilities. These high-level vulnerabilities were actually introduced by the core development team at WordPress. 

In a recent announcement, WordPress claimed to have patched four different core vulnerabilities. These core vulnerabilities were created because of flaws introduced by the development team at WordPress. Here is some more information about these vulnerabilities. 

What are the Four WordPress Vulnerabilities Mentioned in This Announcement? 

The WordPress announcement previously mentioned was not very detailed regarding what core vulnerabilities were discovered. However, the governmental agency in charge of logging and publicizing online security vulnerabilities rated these problems as high as an eight on a scale from one to ten. This agency, known as the United States Government National Vulnerability Database, was created in 2005 to monitor severe online security threats. 

The four WordPress vulnerabilities previously mentioned are:

  • SQL injection via WP_Query caused by improper sanitation (Level 8 security threat)
  • SQL injection in WP_Meta_Query caused by a lack of data sanitization (Level 7.4 security threat)
  • Stored cross-site scripting via authenticated users (Level 6.6 security threat)
  • Authenticate object injection via Multisites (Level 6.6 security threat)

Security researchers who WordPress didn’t employ discovered three of these four security threats. The team at WordPress was completely unaware of these threats until these independent researchers notified them. Once the WordPress team received this information, they started the process of fixing these security vulnerabilities before they were widely publicized. 

Was Rushed Update Development To Blame For These Security Issues?

In 2021, the development of WordPress updates slowed down significantly. In fact, the developers had to delay the 5.9 update to late 2022 due to development issues. Many core developers raised concerns about the pace of update development and how that could affect core security. 

Many development professionals are placing blame for these security vulnerabilities solely on the unrealistic WordPress update calendar. Typically, there are around four WordPress updates a year. However, this has been reduced to three in 2022 on the heels of the news about these core vulnerabilities. 

Many experts in the world of online security suggest that WordPress should focus on releasing fewer updates so they can focus on quality over quantity. These experts believe that few updates would help ensure these types of vulnerabilities aren’t released to the public. 

Where Does WordPress Go From Here?

To their credit, the team at WordPress began fixing the core vulnerabilities in their system as soon as they were notified. If you are currently using WordPress to power your website, then you need to download the latest version of WordPress. Version 5.8.3 contains fixes for these vulnerabilities along with other design updates. 

If you are unsure about how to update your existing WordPress software, then reaching out to a web development professional for assistance is a wise move.

Get Your Free Guide

No spam. Just the guide. Unsubscribe anytime.
Written By
Peter Roesler
Peter Roesler
President & Founder · Small Business SEO

By, Peter Roesler, President of Small Business SEO. 25+ years. One obsession.

Pete started in digital marketing before Google was the default search engine. He's been Google Certified every year since day one. Always barefoot. Never corporate. Still the hungriest person in the room.

5,000+
Clients Served
$200M+
Revenue Generated
100+
#1 Rankings Owned
The Real Reasons AI Search Engines Favor Interactive Websites Over Static Pages
AI & New Search
The Real Reasons AI Search Engines Favor Interactive Websites Over Static Pages

Why is interactive content a must for modern websites? It’s because AI search is changing what a strong website needs to do. A Claude...

Peter Roesler · April 2026
Read Now →
8 Clues Your Headings Are Weakening Your AI Search Performance
AI & New Search
8 Clues Your Headings Are Weakening Your AI Search Performance

Strong content does not always translate into visibility in AI-driven results. Many pages lose ground because their structures fail to clearly communicate intent. Weak...

Peter Roesler · April 2026
Read Now →
Why Your Website Traffic Drops Even When You Keep Publishing New Content
SEO / AEO / GEO
Why Your Website Traffic Drops Even When You Keep Publishing New Content

Traffic should climb when you keep publishing, but for many business owners, the opposite starts to happen. New posts go live, effort stays high,...

Peter Roesler · April 2026
Read Now →
SEO vs Google Ads: Which One Is Right for Your Business?
SEO / AEO / GEO
SEO vs Google Ads: Which One Is Right for Your Business?

Should you spend on SEO or Google Ads to get more leads? The answer depends on your timeline, your market, and how your customers...

Peter Roesler · April 2026
Read Now →
How to Rank on Google Maps
SEO / AEO / GEO
How to Rank on Google Maps

Want to rank higher on Google Maps without wasting time on junk tactics? Google Maps rankings come from clear signals, a clean setup, and...

Peter Roesler · April 2026
Read Now →
25 Years. One Obsession. Jacksonville FL
Stop Losing Online.Start Winning Today.

No pitch. No fluff. One free 30-minute call and you'll know exactly what's costing you customers and how to fix it.

Google Certified · No Contracts · Senior Level Only · Since 2009
5,137+
Businesses Ranked On Google
250%
Average Traffic Lift - Year One
25 Yrs
One Obsession.