The WordPress Security Team has announced that security updates for versions 4.1 through 4.6 will cease in July 2025. This means that any sites still running these outdated versions will no longer receive critical security patches, increasing their vulnerability to attacks.
Why This Matters
With less than 1% of WordPress sites using versions 4.1 to 4.6, the decision to stop updates reflects the diminishing return on the effort required to maintain these older versions. Continuing to support them diverts resources from securing the majority of users on newer versions, which are more widely used and updated.
What You Should Do
Site owners using versions 4.1 to 4.6 should upgrade to the latest version of WordPress as soon as possible. This will ensure that your site remains secure and protected against vulnerabilities that could be exploited by attackers.
What Are the Consequences?
Failing to update could expose your site to security vulnerabilities, making it an easy target for hackers. Without ongoing security updates, any new exploits discovered will leave your site defenseless.
What Notifications Will Users Receive?
Users of outdated versions will see a non-dismissible notice in their admin dashboard, informing them that their version is no longer receiving security updates. This notice will become more prominent as the end date approaches, urging users to take action.
Frequently Asked Questions
When will security updates cease for WordPress versions 4.1 to 4.6?
Security updates will cease in July 2025.
What percentage of sites are using WordPress versions 4.1 to 4.6?
Less than 1% of sites are currently using these versions.
What will happen to users of older WordPress versions?
Users will receive prominent notices in their admin dashboard indicating that their version is no longer receiving security updates.