In a three-month notice, WordPress stated that they will stop all security updates for installations using versions 3.7 to 4.0. An indelible notice will be displayed on the impacted installations for the duration of their use.
WordPress said security updates for WordPress versions 3.7 through 4.0 will stop beginning on December 1, 2022. They said, after the support for these outdated versions of WordPress ends, anyone still using them exposes their websites to hacking attacks.
According to the WordPress core development team by not having to maintain security support for earlier versions, they can concentrate more effectively on updating the most recent versions.
“Versions WordPress 3.7 – 4.0 have reached levels of usage, namely less than 1% of total installs, where the benefit of providing these updates is outweighed by the effort involved…By dropping support for these older versions, the newer versions of WordPress will become more secure as more time can be focused on their needs,” WordPress said on their recent blob on September 7, 2022.
The Security team has a tradition of backporting security improvements to sites running older versions as a courtesy, with the expectation that the sites will be automatically updated.