Vulnerabilities and security researches forcustom-404-pro custom-404-pro
Direction: descendingNov 10, 2025
Custom 404 Pro # CVE-2025-9947
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 11, 2025
- Research Description
- The Custom 404 Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘path’ parameter in all versions up to, and including, 3.12.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
- Affected versions
-
max 3.12.0.
- Status
-
vulnerable
Aug 04, 2024
Custom 404 Pro # CVE-2024-39646
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 02, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kunal Nagar Custom 404 Pro allows Reflected XSS.This issue affects Custom 404 Pro: from n/a through 3.11.1.
- Affected versions
-
max 3.11.2.
- Status
-
vulnerable
Jun 06, 2024
Custom 404 Pro # CVE-2019-14789
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 15, 2019
- Research Description
- The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter.
- Affected versions
-
max 3.7.1.
- Status
-
vulnerable
Custom 404 Pro # CVE-2019-15838
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 30, 2019
- Research Description
- The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789.
- Affected versions
-
max 3.2.8.
- Status
-
vulnerable
Custom 404 Pro # CVE-2023-0385
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 18, 2023
- Research Description
- The Custom 404 Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.1. This is due to missing or incorrect nonce validation on the custom_404_pro_admin_init function. This makes it possible for unauthenticated attackers to delete logs, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
max 3.7.2.
- Status
-
vulnerable
Custom 404 Pro # CVE-2023-32740
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 30, 2023
- Research Description
- Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kunal Nagar Custom 404 Pro plugin <= 3.8.1 versions.
- Affected versions
-
max 3.8.2.
- Status
-
vulnerable
Custom 404 Pro # CVE-2023-51540
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 01, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kunal Nagar Custom 404 Pro allows Stored XSS.This issue affects Custom 404 Pro: from n/a through 3.10.0.
- Affected versions
-
max 3.10.1.
- Status
-
vulnerable
Custom 404 Pro # CVE-2023-2032
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 27, 2023
- Research Description
- The Custom 404 Pro WordPress plugin before 3.8.1 does not properly sanitize database inputs, leading to multiple SQL Injection vulnerabilities.
- Affected versions
-
max 3.7.3.
- Status
-
vulnerable
Custom 404 Pro # CVE-2022-47605
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 12, 2023
- Research Description
- Auth. SQL Injection') vulnerability in Kunal Nagar Custom 404 Pro plugin <= 3.7.0 versions.
- Affected versions
-
max 3.7.3.
- Status
-
vulnerable
Custom 404 Pro # CVE-2023-2023
- CVE, Research URL
- Home page URL
- Application
- Date
- May 30, 2023
- Research Description
- The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.
- Affected versions
-
max 3.7.3.
- Status
-
vulnerable