Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Akismet 3.1.5, released October 13, 2015, fixed a critical cross-site scripting (XSS) vulnerability that affected every version of the WordPress plugin since 2.5.0. Akismet said it had no evidence the flaw had been exploited in the wild, but advised site administrators to update immediately. If your site still runs an old Akismet release, update it and confirm the plugin is active and current.

What was the Akismet security flaw?

Akismet reported that a researcher from Sucuri had notified the company of an XSS vulnerability in its WordPress plugin. XSS is a class of flaw that can allow attacker-controlled script content to run in a visitor’s browser in a vulnerable context. Akismet’s notice did not describe the affected code path in detail, so the precise mechanics should not be inferred from the advisory.

The notice said the vulnerability was theoretically exploitable via comments. Akismet also said it was blocking attempts during the comment-check API call, including on sites that had not yet installed the latest version. That mitigation was not a substitute for installing the security release.

Which Akismet versions were affected?

Akismet’s October 13, 2015 security notice said the bug affected all versions of the Akismet WordPress plugin since version 2.5.0. Version 3.1.5 contained the fix. The advisory did not provide a CVE identifier, CVSS score, proof of concept, or a numerical estimate of affected sites.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The affected range refers to the 2015 flaw; it does not mean that later Akismet releases were also vulnerable to that same issue. The current plugin version is maintained separately from the historical fix.

Was the vulnerability exploited?

Akismet said it had “no evidence that it has been exploited in the wild.” This is the vendor’s assessment at the time of its October 13, 2015 notice, not proof that exploitation was impossible. The advisory did not report a confirmed exploitation count.

What did WordPress do, and why update manually?

WordPress.org’s plugins team enabled automatic updates for vulnerable installations that were eligible to auto-update plugins. Akismet nevertheless told administrators to upgrade as soon as possible. Automatic updates only helped sites able to receive them, so administrators should verify the installed version rather than assume the fix was applied.

How to update Akismet and verify it

  1. Use the WordPress dashboard: Sign in to the site’s admin area and open Dashboard > Updates. If Akismet has an available update, select it and choose Update Plugins. Depending on the WordPress version and configuration, you can also open Plugins > Installed Plugins and use the update control beside Akismet.
  2. Alternatively, use the official directory: Download Akismet from the WordPress.org Akismet plugin page and install or update it through the site’s plugin management workflow.
  3. Confirm the result: Return to Plugins > Installed Plugins and check that Akismet is active and reports the expected current version. Review the site’s front end and its comment or contact-form workflow, and check WordPress for update errors or plugin warnings.

If an update fails, check that the site meets the plugin’s WordPress and PHP requirements, then retry through the dashboard or official plugin directory. For a production site, take a backup before making changes and contact the host or site administrator if filesystem permissions or update errors prevent installation.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Current Akismet version and requirements

The WordPress.org listing currently identifies Akismet Anti-spam: Spam Protection as version 5.7.2, released August 19, 2026. It lists requirements of WordPress 5.8 or later and PHP 7.2 or later, and says it is tested up to WordPress 7.1.2. The listing reports more than 5 million active installations. These are current listing details and may change; check the official plugin page for the latest release and compatibility information.

The directory describes Akismet as free with additional paid commercial upgrades or support. Personal-blog API keys are free; business and commercial sites may require paid subscriptions. The plugin checks comments and contact-form submissions against Akismet’s spam database and provides comment-history and moderation tools, according to its WordPress.org listing.

The current changelog records version 5.7 on April 23, 2026. It notes Abilities API support for statistics and comment checking, support for the upcoming Connectors page, improvements to automated-spam detection and comment-history sorting for invalid data, and safer inline script output using wp_get_inline_script_tag(), among other security enhancements. Those notes describe a later release; they should not be confused with the specific XSS fix shipped in 3.1.5 in 2015.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.