Extension WordPress
Vulnérabilités Custom 404 Pro
Cette page rassemble les failles publiées pour Custom 404 Pro, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Custom 404 Pro
12 fiches
Custom 404 Pro <= 3.12.0 – Authenticated (Administrator+) SQL Injection via `path` Parameter
The Custom 404 Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘path’ parameter in all versions up to, and including, 3.12.0 due to insufficient escaping on the user supplied parameter and lack of sufficient…
*-3.12.0
Non indiqué
10/10/2025
Custom 404 Pro <= 3.12.0 – Cross-Site Request Forgery
The Custom 404 Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated…
*-3.12.0
3.12.1
13/05/2025
Custom 404 Pro <= 3.11.1 – Reflected Cross-Site Scripting
The Custom 404 Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'c4pmessageType' and 'c4pmessage' parameters in versions up to, and including, 3.11.1 due to insufficient input sanitization and output escaping. This makes it possible…
*-3.11.1
3.11.2
01/08/2024
Custom 404 Pro <= 3.10.0 – Unauthenticated Stored Cross-Site Scripting via logging
The Custom 404 Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several logged parameters in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for…
*-3.10.0
3.10.1
27/12/2023
Custom 404 Pro <= 3.8.1 – Reflected Cross-Site Scripting via 'page'
The Custom 404 Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-3.8.1
3.8.2
15/05/2023
Custom 404 Pro <= 3.7.2 – Reflected Cross-Site Scripting via 's'
The Custom 404 Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in versions up to, and including, 3.7.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-3.7.2
3.7.3
02/05/2023
Custom 404 Pro <= 3.8.0 – Unauthenticated SQL Injection via 's'
The Custom 404 Pro plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in versions up to, and including, 3.8.0 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on…
*-3.8.0
3.8.1
25/04/2023
Custom 404 Pro <= 3.7.2 – Unauthenticated SQL Injection
The Custom 404 Pro plugin for WordPress is vulnerable to blind SQL Injection via multiple parameters including the 'User-Agent' and 'Referer' Headers in versions up to, and including, 3.7.2 due to insufficient escaping on the user supplied parameters…
[*, 3.7.3)
3.7.3
25/04/2023
Custom 404 Pro <= 3.7.1 – Cross-Site Request Forgery
The Custom 404 Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.1. This is due to missing or incorrect nonce validation on the custom_404_pro_admin_init function. This makes it possible for…
*-3.7.1
3.7.2
18/01/2023
Custom 404 Pro <= 3.7.0 – Authenticated (Administrator+) SQL Injection
The Custom 404 Pro plugin for WordPress is vulnerable to blind SQL Injection via the ‘path’ parameter in versions up to, and including, 3.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-3.7.0
3.7.1
13/01/2023
Custom 404 Pro <= 3.2.8 – Reflected Cross-Site Scripting
The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter.
[*, 3.2.9)
3.2.9
25/06/2019
Custom 404 Pro <= 3.2.7 – Reflected Cross-Site Scripting
The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789.
[*, 3.2.8)
3.2.8
24/06/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.