Dropping security updates for WordPress versions 4.1 through 4.6
As of July 2025 the WordPress Security Team no longer provides security updates for WordPress versions 4.1 through 4.6. These branches are nine or more years old and over 99% of WordPress installations run newer versions, so exposure is limited — but any site still on 4.1–4.6 is now permanently unpatched and should upgrade as soon as possible.
Affected Versions
4.1
What this means under a SharedLicense license
Sites on WordPress 4.1–4.6 accumulate unpatched vulnerabilities from that point on; every flaw disclosed after July 2025 applies to them indefinitely.
As of July 2025, the WordPress Security Team will no longer provide security updates for WordPress versions 4.1 through 4.6.
These versions were first released nine or more years ago and over 99% of WordPress installations run a more recent version. The chances this will affect your site, or sites, is very small.
If you are unsure if you are running an up-to-date version of WordPress, please log in to your site’s dashboard. Out of date versions will display a notice that looks like this:

The version you are running is displayed in the bottom of the “At a Glance” section of the dashboard.

As a reminder, the only actively supported version of WordPress is the most recent one. Security updates are only backported to older branches as a courtesy.
The Make WordPress Security blog has further details about the process to end support.
Share this:
Frequently Asked Questions
Which WordPress versions lost security updates?
How do I check my WordPress version?
Which WordPress versions are still supported?
What should I do if my site runs WordPress 4.1–4.6?
References
Check your system for vulnerabilities
Select your product and operating system to see the exact fix commands that apply to you.
Check Your System