404 Solution [404-solution] < 3.1.1
unknown
[en] The 404 Solution plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This is due to improper sanitization of the `filterText` parameter in the `ajaxU...
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.1
- Disclosed:
- Dec 13, 2025
CVE-2025-14477 on NVD →
404 Solution <= 3.1.0 - Authenticated (Admin+) SQL Injection via 'filterText' Parameter
medium
The 404 Solution plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This is due to improper sanitization of the `filterText` parameter in the `ajaxUpdate...
- CVSS:
- 4.9
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.1
- Disclosed:
- Dec 12, 2025
CVE-2025-14477 on NVD →
404 Solution [404-solution] < 2.35.20
unknown
[en] The 404 Solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 2.35.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...
- Affected:
- up to 2.35.20
- Fixed in:
- 2.35.20
- Disclosed:
- Nov 20, 2024
CVE-2024-11277 on NVD →
404 Solution <= 2.35.19 - Reflected Cross-Site Scripting
medium
The 404 Solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 2.35.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...
- CVSS:
- 6.1
- Affected:
- up to 2.35.19
- Fixed in:
- 2.35.20
- Disclosed:
- Nov 19, 2024
CVE-2024-11277 on NVD →
404 Solution [404-solution] < 2.35.18
unknown
[en] The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.35.17 via the export feature. This makes it possible for unauthenticated attackers to extract sensitive data such as redirects including GET parameters which may reveal sensitive informatio...
- Affected:
- up to 2.35.18
- Fixed in:
- 2.35.18
- Disclosed:
- Nov 16, 2024
CVE-2024-11094 on NVD →
404 Solution <= 2.35.17 - Missing Authentication to Sensitive Information Exposure
medium
The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.35.17 via the export feature. This makes it possible for unauthenticated attackers to extract data such as redirects including GET parameters which may reveal sensitive information. On most site...
- CVSS:
- 5.3
- Affected:
- up to 2.35.17
- Fixed in:
- 2.35.18
- Disclosed:
- Nov 15, 2024
CVE-2024-11094 on NVD →
404 Solution [404-solution] < 2.35.8
unknown
[en] The 404 Solution WordPress plugin before 2.35.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins.
- Affected:
- up to 2.35.8
- Fixed in:
- 2.35.8
- Disclosed:
- Mar 11, 2024
CVE-2024-1068 on NVD →
404 Solution <= 2.35.7 - Authenticated (Admin+) SQL Injection
critical
The 404 Solution plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.35.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access...
- CVSS:
- 9.1
- Affected:
- up to 2.35.7
- Fixed in:
- 2.35.8
- Disclosed:
- Feb 17, 2024
CVE-2024-1068 on NVD →
404 Solution [404-solution] < 2.33.1
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Aaron J 404 Solution.This issue affects 404 Solution: from n/a through 2.33.0.
- Affected:
- up to 2.33.1
- Fixed in:
- 2.33.1
- Disclosed:
- Jan 5, 2024
CVE-2023-52146 on NVD →
404 Solution <= 2.33.0 - Sensitive Information Exposure via Log File
medium
The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.33.0 via the plugin's log file. This makes it possible for unauthenticated attackers to extract sensitive data including plugin configuration and debug data.
- CVSS:
- 5.3
- Affected:
- up to 2.33.0
- Fixed in:
- 2.33.1
- Disclosed:
- Dec 28, 2023
CVE-2023-52146 on NVD →
404 Solution [404-solution] < 2.35.0
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aaron J 404 Solution.This issue affects 404 Solution: from n/a through 2.34.0.
- Affected:
- up to 2.35.0
- Fixed in:
- 2.35.0
- Disclosed:
- Dec 28, 2023
CVE-2023-50848 on NVD →
404 Solution <= 2.34.0 - Authenticated(Administrator+) SQL Injection
medium
The 404 Solution plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to 2.35.0 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with admin...
- CVSS:
- 6.6
- Affected:
- up to 2.35.0
- Fixed in:
- 2.35.0
- Disclosed:
- Dec 21, 2023
CVE-2023-50848 on NVD →
404 Solution [404-solution] < 2.34.0
unknown
Update the WordPress 404 Solution plugin to the latest available version (at least 2.34.0).
WordFence discovered and reported this SQL Injection vulnerability in WordPress 404 Solution Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information....
- Affected:
- up to 2.34.0
- Fixed in:
- 2.34.0
- Disclosed:
- Oct 26, 2023
404 Solution <= 2.33.2 - Authenticated (Administrator+) SQL Injection via orderby
high
The 404 Solution plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.33.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, wit...
- CVSS:
- 7.2
- Affected:
- up to 2.34.0
- Fixed in:
- 2.34.0
- Disclosed:
- Oct 23, 2023
404 Solution [404-solution] < 2.34.0
unknown
The 404 Solution plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.33.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, wit...
- Affected:
- up to 2.34.0
- Fixed in:
- 2.34.0
- Disclosed:
- Oct 23, 2023
404 Solution <= 2.33.0 - Sensitive Information Exposure
medium
The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.33.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 2.33.0
- Fixed in:
- 2.33.1
- Disclosed:
- Oct 16, 2023
404 Solution [404-solution] < 2.33.1
unknown
The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.33.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- Affected:
- up to 2.33.1
- Fixed in:
- 2.33.1
- Disclosed:
- Oct 16, 2023
404 Solution [404-solution] < 2.33.1
unknown
The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.33.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- Affected:
- up to 2.33.1
- Fixed in:
- 2.33.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database