{"error":0,"message":null,"data":{"name":"Custom 404 Pro","plugin":"custom-404-pro","link":"https:\/\/wordpress.org\/plugins\/custom-404-pro\/","latest":"1788058260","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"1b2f8d07a1a9006f0b60382d5300f81260d080df641310dfbb938bd40cef27b9","name":"Custom 404 Pro [custom-404-pro] < 3.2.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-15838","name":"CVE-2019-15838","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-15838","description":"[en] The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789.","date":"2019-08-30"},{"id":"617ec72b-124b-4612-97a7-d69a29892338","name":"wpscan.com","link":"https:\/\/wpscan.com\/vulnerability\/617ec72b-124b-4612-97a7-d69a29892338","description":null,"date":null},{"id":"4ec187d5bad0e511183293ab6f3a4e7069eef9a1","name":"Custom 404 Pro <= 3.2.7 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/custom-404-pro\/custom-404-pro-327-reflected-cross-site-scripting","description":"The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789.","date":"2019-06-24"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"7acbc7d15eed7ac60d09300bd881c15b31e48b107ec7c1c3852ee900fd0d4141","name":"Custom 404 Pro [custom-404-pro] < 3.2.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-14789","name":"CVE-2019-14789","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-14789","description":"[en] The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin\/admin.php?page=c4p-main page parameter.","date":"2019-08-15"},{"id":"81ee1df5-12dc-49d8-8d49-ca28d6f5b7fd","name":"Custom 404 Pro &lt; 3.2.9 - Authenticated Reflected XSS","link":"https:\/\/wpscan.com\/vulnerability\/81ee1df5-12dc-49d8-8d49-ca28d6f5b7fd","description":"The Custom 404 Pro WordPress plugin was affected by an Authenticated Reflected XSS security vulnerability.","date":null},{"id":"b672a22b8ccc8c2c4c4e0ad525000986d500dbe7","name":"Custom 404 Pro <= 3.2.8 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/custom-404-pro\/custom-404-pro-328-reflected-cross-site-scripting","description":"The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin\/admin.php?page=c4p-main page parameter.","date":"2019-06-25"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"b950f82cbf00ae7f92d3cf4977326b86fcf52a23293fb4290ae01e82cac28286","name":"Custom 404 Pro [custom-404-pro] < 3.2.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1ddf3e19bca28cf11a5802e8a2abfb797e40131d","name":"WordPress Custom 404 Pro plugin <= 3.2.7 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/custom-404-pro\/vulnerability\/wordpress-custom-404-pro-plugin-3-2-7-authenticated-reflected-cross-site-scripting-xss-vulnerability","description":"Authenticated Reflected Cross-Site Scripting (XSS) vulnerability found in WordPress Custom 404 Pro plugin (versions <= 3.2.7).","date":"2019-06-25"}],"impact":[]},{"uuid":"f8a28c2d488651def90a181445ac9fb9eb4f11b9848df50b2089e16ae5ea0227","name":"Custom 404 Pro [custom-404-pro] < 3.7.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.7.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"933aa21ae47cc9a218be1c7c2d06becb0052d1f7","name":"Custom 404 Pro <= 3.7.0 - Authenticated (Administrator+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/custom-404-pro\/custom-404-pro-370-authenticated-administrator-sql-injection","description":"The Custom 404 Pro plugin for WordPress is vulnerable to blind SQL Injection via the \u2018path\u2019 parameter in versions up to, and including, 3.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with administrator access or higher to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2023-01-13"},{"id":"CVE-2022-47605","name":"CVE-2022-47605","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-47605","description":"[en] Auth. SQL Injection') vulnerability in Kunal Nagar Custom 404 Pro plugin <=\u00a03.7.0 versions.","date":"2023-04-12"},{"id":"e0f6039ba7f356bab330bd1bff650585ac590b01","name":"WordPress  Custom 404 Pro Plugin  <= 3.7.0 is vulnerable to SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/custom-404-pro\/vulnerability\/wordpress-custom-404-pro-plugin-3-7-0-admin-sql-injection-vulnerability","description":"Update the WordPress Custom 404 Pro plugin to the latest available version (at least 3.7.1).\nminhtuanact discovered and reported this SQL Injection vulnerability in WordPress Custom 404 Pro Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information and creating new administrator accounts. This vulnerability has been fixed in version 3.7.1.","date":"2023-01-16"},{"id":"313d55bd-22d7-4714-9e6e-ef55c8ea23b6","name":"Custom 404 Pro &lt; 3.7.1 - Admin+ SQLi","link":"https:\/\/wpscan.com\/vulnerability\/313d55bd-22d7-4714-9e6e-ef55c8ea23b6","description":"The plugin does not properly sanitise and escape the path parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:U\/C:H\/I:H\/A:L","av":"n","ac":"l","pr":"h","ui":"r","s":"u","c":"h","i":"h","a":"l","score":"8.3","severity":"h","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:U\/C:H\/I:H\/A:L","score":"8.3","severity":"high","av":"network","ac":"low","pr":"high","ui":"required","s":"unchanged","c":"high","i":"high","a":"low","exploitable":"1.2","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"bce71b12b874d6c94ad1de52755ef5e5664fb42013115b457250468666d36214","name":"Custom 404 Pro [custom-404-pro] < 3.7.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.7.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-0385","name":"CVE-2023-0385","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-0385","description":"[en] The Custom 404 Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.1. This is due to missing or incorrect nonce validation on the custom_404_pro_admin_init function. This makes it possible for unauthenticated attackers to delete logs, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-01-18"},{"id":"8ac136f52b7b708ede6f038255687c27ae0b897a","name":"Custom 404 Pro <= 3.7.1 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/custom-404-pro\/custom-404-pro-371-cross-site-request-forgery","description":"The Custom 404 Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.1. This is due to missing or incorrect nonce validation on the custom_404_pro_admin_init function. This makes it possible for unauthenticated attackers to delete logs, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-01-18"},{"id":"ed6216709f2714274d08992402fa98043a996325","name":"WordPress  Custom 404 Pro Plugin  <= 3.7.1 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/custom-404-pro\/vulnerability\/wordpress-custom-404-pro-plugin-3-7-1-cross-site-request-forgery-vulnerability","description":"Update the WordPress Custom 404 Pro plugin to the latest available version (at least 3.7.2).\nMarco Wotschka  discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Custom 404 Pro Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. For example a password change which will then allow the malicious actor to login into the admin account. This vulnerability has been fixed in version 3.7.2.","date":"2023-01-18"},{"id":"1e7ca070-b37a-41fc-af9a-bc6469073fd9","name":"Custom 404 Pro &lt; 3.7.2 - Logs Deletion via CSRF","link":"https:\/\/wpscan.com\/vulnerability\/1e7ca070-b37a-41fc-af9a-bc6469073fd9","description":"The plugin does not have CSRF check when deleting logs, which could allow attackers to make logged in admins perform such action via a CSRF attack","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"97662d0b83947494fca69dccb9d4533f5cbd2c016c018d735d0e41ac86e8771f","name":"Custom 404 Pro [custom-404-pro] < 3.7.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.7.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"a1f153b765cc608e41ff9617f28a88e56f6c0186","name":"WordPress  Custom 404 Pro Plugin  <= 3.7.2 is vulnerable to SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/custom-404-pro\/vulnerability\/wordpress-custom-404-pro-plugin-3-7-2-unauth-sql-injection-sqli-vulnerability","description":"Update the WordPress Custom 404 Pro plugin to the latest available version (at least 3.7.3).\nAn unknown person discovered and reported this SQL Injection vulnerability in WordPress Custom 404 Pro Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 3.7.3.","date":"2023-04-25"}],"impact":[]},{"uuid":"9996ae8ce25df5bb7504e796230c0f1c3b15c2e49473114a086c6969c170188e","name":"Custom 404 Pro [custom-404-pro] < 3.7.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.7.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-2023","name":"CVE-2023-2023","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-2023","description":"[en] The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.","date":"2023-05-30"},{"id":"0060fb31d74bc32f91bbf8015f8482e1fcd459e1","name":"WordPress  Custom 404 Pro Plugin  < 3.7.3 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/custom-404-pro\/vulnerability\/wordpress-custom-404-pro-plugin-3-7-3-reflected-cross-site-scripting-vulnerability","description":"Update the WordPress Custom 404 Pro plugin to the latest available version (at least 3.7.3).\nChien Vuong discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Custom 404 Pro Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.7.3.","date":"2023-05-11"},{"id":"4181f8c9a0b4ff5e74a3db36c5cfc01e062a4c10","name":"Custom 404 Pro <= 3.7.2 - Reflected Cross-Site Scripting via 's'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/custom-404-pro\/custom-404-pro-372-reflected-cross-site-scripting-via-s","description":"The Custom 404 Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u2018s\u2019 parameter in versions up to, and including, 3.7.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2023-05-02"},{"id":"8859843a-a8c2-4f7a-8372-67049d6ea317","name":"Custom 404 Pro &lt; 3.7.3 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/8859843a-a8c2-4f7a-8372-67049d6ea317","description":"The plugin does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f2512dec84fc482239ebf44e57f9bb088332c0f13ca0279c5bd97bb88506e545","name":"Custom 404 Pro [custom-404-pro] < 3.8.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-32740","name":"CVE-2023-32740","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-32740","description":"[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kunal Nagar Custom 404 Pro plugin <=\u00a03.8.1 versions.","date":"2023-08-30"},{"id":"4752c29cda6d0c76e03fcd60cde9680d70012c5e","name":"WordPress  Custom 404 Pro Plugin  <= 3.8.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/custom-404-pro\/vulnerability\/wordpress-custom-404-pro-plugin-3-8-1-reflected-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Custom 404 Pro plugin to the latest available version (at least 3.8.2).\nLEE SE HYOUNG (hackintoanetwork) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Custom 404 Pro Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.8.2.","date":"2023-05-15"},{"id":"4f6079a08268f1d8920ed4b4bebfceb35675aacd","name":"Custom 404 Pro <= 3.8.1 - Reflected Cross-Site Scripting via 'page'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/custom-404-pro\/custom-404-pro-381-reflected-cross-site-scripting-via-page","description":"The Custom 404 Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u2018page\u2019 parameter in versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2023-05-15"},{"id":"badb8c0b-61ec-4039-aac2-35d7b22502fb","name":"Custom 404 Pro &lt; 3.8.2 - Reflected XSS","link":"https:\/\/wpscan.com\/vulnerability\/badb8c0b-61ec-4039-aac2-35d7b22502fb","description":"The plugin does not sanitise and escape some parameters before outputting them back in the page, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"h","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"5.8","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"5.8","severity":"medium","av":"network","ac":"high","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"fbee2c14c5190abd4ff1825de9eff45099c811f605ae41bcd756ca3281bd55c0","name":"Custom 404 Pro [custom-404-pro] < 3.8.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.8.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-2032","name":"CVE-2023-2032","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-2032","description":"[en] The Custom 404 Pro WordPress plugin before 3.8.1 does not properly sanitize database inputs, leading to multiple SQL Injection vulnerabilities.","date":"2023-06-27"},{"id":"297aa90c745948d6356d1ee10634cf8a9e249293","name":"WordPress  Custom 404 Pro Plugin  < 3.8.1 is vulnerable to SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/custom-404-pro\/vulnerability\/wordpress-custom-404-pro-plugin-3-8-1-multiple-sql-injection-vulnerability","description":"Update the WordPress Custom 404 Pro plugin to the latest available version (at least 3.8.1).\nAlex Sanford discovered and reported this SQL Injection vulnerability in WordPress Custom 404 Pro Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 3.8.1.","date":"2023-06-22"},{"id":"219736f570bd2089b52b5a4f328420e84fc189d0","name":"Custom 404 Pro <= 3.8.0 - Unauthenticated SQL Injection via 's'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/custom-404-pro\/custom-404-pro-380-unauthenticated-sql-injection-via-s","description":"The Custom 404 Pro plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in versions up to, and including, 3.8.0 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2023-04-25"},{"id":"17acde5d-44ea-4e77-8670-260d22e28ffe","name":"Custom 404 Pro &lt; 3.8.1 - Multiple SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/17acde5d-44ea-4e77-8670-260d22e28ffe","description":"The plugin does not properly sanitize database inputs, leading to multiple SQL Injection vulnerabilities.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"f14d3eb1e92e9e5be422db4aba6bf76dec901a65bad381f48f285fdfd7818c4f","name":"Custom 404 Pro [custom-404-pro] < 3.7.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.7.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"21d4716e02cad34abf9292de40bce6f819fa5f8e","name":"Custom 404 Pro <= 3.7.2 - Unauthenticated SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/custom-404-pro\/custom-404-pro-372-unauthenticated-sql-injection","description":"The Custom 404 Pro plugin for WordPress is vulnerable to blind SQL Injection via multiple parameters including the 'User-Agent' and 'Referer' Headers in versions up to, and including, 3.7.2 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query.  This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2023-04-25"}],"impact":[]},{"uuid":"5df62fb235116176acecae9a4056b60b1468a9d997858ef347c5ba1a1ee29624","name":"Custom 404 Pro [custom-404-pro] < 3.10.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.10.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-51540","name":"CVE-2023-51540","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-51540","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kunal Nagar Custom 404 Pro allows Stored XSS.This issue affects Custom 404 Pro: from n\/a through 3.10.0.","date":"2024-02-01"},{"id":"fee8d1d09d138ffc27a63ea7a478888e3bd077db","name":"WordPress  Custom 404 Pro Plugin  <= 3.10.0 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/custom-404-pro\/vulnerability\/wordpress-custom-404-pro-plugin-3-10-0-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Custom 404 Pro plugin to the latest available version (at least 3.10.1).\nKyle Sanchez discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Custom 404 Pro Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.10.1.\nHave additional information or questions about this entry? Get in touch.","date":"2024-12-27"},{"id":"72df5d340c86e9d165d9557ade27cc049a5aa3b2","name":"Custom 404 Pro <= 3.10.0 - Unauthenticated Stored Cross-Site Scripting via logging","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/custom-404-pro\/custom-404-pro-3100-unauthenticated-stored-cross-site-scripting-via-logging","description":"The Custom 404 Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several logged parameters in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-12-27"},{"id":"042d2d4b-d6f3-47be-b3b7-a882253840ba","name":"Custom 404 Pro &lt; 3.10.1 - Unauthenticated Stored Cross-Site Scripting via logging","link":"https:\/\/wpscan.com\/vulnerability\/042d2d4b-d6f3-47be-b3b7-a882253840ba","description":"The Custom 404 Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several logged parameters in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"dfffa5c8ad76c4cff1eaa1e62fb594a011d4f51e56a378974c3b3f1aa16c0b2d","name":"Custom 404 Pro [custom-404-pro] < 3.11.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.11.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-39646","name":"CVE-2024-39646","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-39646","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kunal Custom 404 Pro custom-404-pro.This issue affects Custom 404 Pro: from n\/a through <= 3.11.1.","date":"2024-08-01"},{"id":"791dcfe86bc18c9246b9ba933c769e94dd984d95","name":"WordPress Custom 404 Pro Plugin <= 3.11.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/custom-404-pro\/vulnerability\/wordpress-custom-404-pro-plugin-3-11-1-reflected-cross-site-scripting-xss-vulnerability","description":"<p>WordPress Custom 404 Pro Plugin <= 3.11.1 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Custom 404 Pro<\/p><p>Link: https:\/\/wordpress.org\/plugins\/custom-404-pro\/#developers<\/p><p>Affected Version <= 3.11.1<\/p><p>Fixed in version 3.11.2 <\/p>","date":"2024-08-01"},{"id":"cb93c281d0486d847b3b24ba712f5b53cc0010e3","name":"Custom 404 Pro <= 3.11.1 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/custom-404-pro\/custom-404-pro-3111-reflected-cross-site-scripting","description":"The Custom 404 Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'c4pmessageType' and 'c4pmessage' parameters in versions up to, and including, 3.11.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2024-08-01"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f9c457315784df7b58dd9c60df46426d435bda5ee7be220dc275725616bb32a4","name":"Custom 404 Pro [custom-404-pro] <= 3.12.0 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.12.0","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2025-9947","name":"Custom 404 Pro <= 3.12.0 - Authenticated (Administrator+) SQL Injection via `path` Parameter","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-9947","description":"The Custom 404 Pro plugin for WordPress is vulnerable to time-based SQL Injection via the \u2018path\u2019 parameter in all versions up to, and including, 3.12.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"0000-00-00"},{"id":"c6dc0ec4e68e4074bd741ea1717799945c34a9ea","name":"WordPress Custom 404 Pro Plugin <= 3.12.0 is vulnerable to SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/custom-404-pro\/vulnerability\/wordpress-custom-404-pro-plugin-3-12-0-authenticated-administrator-sql-injection-via-path-parameter-vulnerability","description":"<p>WordPress Custom 404 Pro Plugin <= 3.12.0 is vulnerable to SQL Injection<\/p><p>Software: Custom 404 Pro<\/p><p>Affected Version <= 3.12.0<\/p><p>CVE: CVE-2025-9947<\/p>","date":"2025-10-13"},{"id":"b6ca2b783709bbf2f694bc906fa99e2bad48c4f9","name":"Custom 404 Pro <= 3.12.0 - Authenticated (Administrator+) SQL Injection via `path` Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/custom-404-pro\/custom-404-pro-3120-authenticated-administrator-sql-injection-via-path-parameter","description":"The Custom 404 Pro plugin for WordPress is vulnerable to time-based SQL Injection via the \u2018path\u2019 parameter in all versions up to, and including, 3.12.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2025-10-10"},{"id":"EUVD-2025-33841","name":"EUVD-2025-33841","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-33841","description":"The Custom 404 Pro plugin for WordPress is vulnerable to time-based SQL Injection via the \u2018path\u2019 parameter in all versions up to, and including, 3.12.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2025-10-11"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"4.9","severity":"m","exploitable":"1.2","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"4.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"1.2","impact":"3.6"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"62da66355a62f0606af99656d9b8ce65c7ac3a2f6e771cc8949971600f9766a2","name":"Custom 404 Pro [custom-404-pro] < 3.12.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.12.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-62880","name":"CVE-2025-62880","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-62880","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in Kunal Nagar Custom 404 Pro allows Cross Site Request Forgery.This issue affects Custom 404 Pro: from n\/a through 3.12.0.","date":"2025-12-22"},{"id":"8bbec5cb278f32b9a097fe393eca31405c228031","name":"Custom 404 Pro <= 3.12.0 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/custom-404-pro\/custom-404-pro-3120-cross-site-request-forgery","description":"The Custom 404 Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2025-05-13"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1777132776"}