plugin

404 Solution Vulnerabilities

18 known security issues reported for the 404 Solution WordPress plugin. Most recent disclosed Dec 13, 2025.

1 critical 1 high 6 medium

Running 404 Solution on your site? Check whether your installed version is affected.

Scan your site free

404 Solution [404-solution] < 3.1.1

unknown

[en] The 404 Solution plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This is due to improper sanitization of the `filterText` parameter in the `ajaxU...

Affected:
up to 3.1.1
Fixed in:
3.1.1
Disclosed:
Dec 13, 2025

CVE-2025-14477 on NVD →

404 Solution <= 3.1.0 - Authenticated (Admin+) SQL Injection via 'filterText' Parameter

medium

The 404 Solution plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This is due to improper sanitization of the `filterText` parameter in the `ajaxUpdate...

CVSS:
4.9
Affected:
up to 3.1.0
Fixed in:
3.1.1
Disclosed:
Dec 12, 2025

CVE-2025-14477 on NVD →

404 Solution [404-solution] < 2.35.20

unknown

[en] The 404 Solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 2.35.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...

Affected:
up to 2.35.20
Fixed in:
2.35.20
Disclosed:
Nov 20, 2024

CVE-2024-11277 on NVD →

404 Solution <= 2.35.19 - Reflected Cross-Site Scripting

medium

The 404 Solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 2.35.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...

CVSS:
6.1
Affected:
up to 2.35.19
Fixed in:
2.35.20
Disclosed:
Nov 19, 2024

CVE-2024-11277 on NVD →

404 Solution [404-solution] < 2.35.18

unknown

[en] The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.35.17 via the export feature. This makes it possible for unauthenticated attackers to extract sensitive data such as redirects including GET parameters which may reveal sensitive informatio...

Affected:
up to 2.35.18
Fixed in:
2.35.18
Disclosed:
Nov 16, 2024

CVE-2024-11094 on NVD →

404 Solution <= 2.35.17 - Missing Authentication to Sensitive Information Exposure

medium

The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.35.17 via the export feature. This makes it possible for unauthenticated attackers to extract data such as redirects including GET parameters which may reveal sensitive information. On most site...

CVSS:
5.3
Affected:
up to 2.35.17
Fixed in:
2.35.18
Disclosed:
Nov 15, 2024

CVE-2024-11094 on NVD →

404 Solution [404-solution] < 2.35.8

unknown

[en] The 404 Solution WordPress plugin before 2.35.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admins.

Affected:
up to 2.35.8
Fixed in:
2.35.8
Disclosed:
Mar 11, 2024

CVE-2024-1068 on NVD →

404 Solution <= 2.35.7 - Authenticated (Admin+) SQL Injection

critical

The 404 Solution plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.35.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access...

CVSS:
9.1
Affected:
up to 2.35.7
Fixed in:
2.35.8
Disclosed:
Feb 17, 2024

CVE-2024-1068 on NVD →

404 Solution [404-solution] < 2.33.1

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Aaron J 404 Solution.This issue affects 404 Solution: from n/a through 2.33.0.

Affected:
up to 2.33.1
Fixed in:
2.33.1
Disclosed:
Jan 5, 2024

CVE-2023-52146 on NVD →

404 Solution <= 2.33.0 - Sensitive Information Exposure via Log File

medium

The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.33.0 via the plugin's log file. This makes it possible for unauthenticated attackers to extract sensitive data including plugin configuration and debug data.

CVSS:
5.3
Affected:
up to 2.33.0
Fixed in:
2.33.1
Disclosed:
Dec 28, 2023

CVE-2023-52146 on NVD →

404 Solution [404-solution] < 2.35.0

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aaron J 404 Solution.This issue affects 404 Solution: from n/a through 2.34.0.

Affected:
up to 2.35.0
Fixed in:
2.35.0
Disclosed:
Dec 28, 2023

CVE-2023-50848 on NVD →

404 Solution <= 2.34.0 - Authenticated(Administrator+) SQL Injection

medium

The 404 Solution plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to 2.35.0 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with admin...

CVSS:
6.6
Affected:
up to 2.35.0
Fixed in:
2.35.0
Disclosed:
Dec 21, 2023

CVE-2023-50848 on NVD →

404 Solution [404-solution] < 2.34.0

unknown

Update the WordPress 404 Solution plugin to the latest available version (at least 2.34.0). WordFence discovered and reported this SQL Injection vulnerability in WordPress 404 Solution Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information....

Affected:
up to 2.34.0
Fixed in:
2.34.0
Disclosed:
Oct 26, 2023

404 Solution <= 2.33.2 - Authenticated (Administrator+) SQL Injection via orderby

high

The 404 Solution plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.33.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, wit...

CVSS:
7.2
Affected:
up to 2.34.0
Fixed in:
2.34.0
Disclosed:
Oct 23, 2023

404 Solution [404-solution] < 2.34.0

unknown

The 404 Solution plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.33.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, wit...

Affected:
up to 2.34.0
Fixed in:
2.34.0
Disclosed:
Oct 23, 2023

404 Solution <= 2.33.0 - Sensitive Information Exposure

medium

The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.33.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 2.33.0
Fixed in:
2.33.1
Disclosed:
Oct 16, 2023

404 Solution [404-solution] < 2.33.1

unknown

The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.33.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

Affected:
up to 2.33.1
Fixed in:
2.33.1
Disclosed:
Oct 16, 2023

404 Solution [404-solution] < 2.33.1

unknown

The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.33.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

Affected:
up to 2.33.1
Fixed in:
2.33.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database