plugin

Wp Crontrol Vulnerabilities

8 known security issues reported for the Wp Crontrol WordPress plugin. Most recent disclosed Aug 21, 2025.

1 high 2 medium

Running Wp Crontrol on your site? Check whether your installed version is affected.

Scan your site free

WP Crontrol - 1.17.0 - 1.19.1 - Authenticated (Administrator+) Blind Server-Side Request Forgery

medium

The WP Crontrol plugin for WordPress is vulnerable to blind Server-Side Request Forgery in versions 1.17.0 to 1.19.1 via the 'wp_remote_request' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web a...

CVSS:
5.9
Affected:
1.17.0 – 1.19.1
Fixed in:
1.19.2
Disclosed:
Aug 21, 2025

CVE-2025-8678 on NVD →

WP Crontrol [wp-crontrol] < 1.16.2 (closed)

unknown

[en] WP Crontrol controls the cron events on WordPress websites. WP Crontrol includes a feature that allows administrative users to create events in the WP-Cron system that store and execute PHP code subject to the restrictive security permissions documented here. While there is no known vulnerability in this feature...

Affected:
up to 1.16.2
Fixed in:
1.16.2
Disclosed:
Mar 25, 2024

CVE-2024-28850 on NVD →

WP Crontrol <= 1.16.1 - Remote Code Execution

high

The WP Crontrol plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.1 when another vulnerability is present on the site that allows access to editing the database. This makes it possible for attackers to execute code on the server. Please see the advisory in references...

CVSS:
7.5
Affected:
up to 1.16.1
Fixed in:
1.16.2
Disclosed:
Mar 24, 2024

CVE-2024-28850 on NVD →

WP Crontrol < 1.3 - Reflected Cross-Site Scripting

medium

The WP Crontrol for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can su...

CVSS:
6.1
Affected:
up to 1.3
Fixed in:
1.3
Disclosed:
Aug 21, 2015

WP Crontrol [wp-crontrol] < 1.3 (closed)

unknown

Because of this vulnerability, authenticated administrators can store HTML and JS code. Vulnerable parameters: "id[hookname]", "id[sig]", "id[next_run]", "id[args][code]". Update the plugin.

Affected:
up to 1.3
Fixed in:
1.3
Disclosed:
Aug 21, 2015

WP Crontrol [wp-crontrol] < 1.3 (closed)

unknown

The WP Crontrol for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can su...

Affected:
up to 1.3
Fixed in:
1.3
Disclosed:
Aug 21, 2015

WP Crontrol [wp-crontrol] < 1.3 (closed)

unknown

The WP Crontrol WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 1.3
Fixed in:
1.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database