WP Crontrol - 1.17.0 - 1.19.1 - Authenticated (Administrator+) Blind Server-Side Request Forgery
medium
The WP Crontrol plugin for WordPress is vulnerable to blind Server-Side Request Forgery in versions 1.17.0 to 1.19.1 via the 'wp_remote_request' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web a...
- CVSS:
- 5.9
- Affected:
- 1.17.0 – 1.19.1
- Fixed in:
- 1.19.2
- Disclosed:
- Aug 21, 2025
CVE-2025-8678 on NVD →
WP Crontrol [wp-crontrol] < 1.16.2 (closed)
unknown
[en] WP Crontrol controls the cron events on WordPress websites. WP Crontrol includes a feature that allows administrative users to create events in the WP-Cron system that store and execute PHP code subject to the restrictive security permissions documented here. While there is no known vulnerability in this feature...
- Affected:
- up to 1.16.2
- Fixed in:
- 1.16.2
- Disclosed:
- Mar 25, 2024
CVE-2024-28850 on NVD →
WP Crontrol <= 1.16.1 - Remote Code Execution
high
The WP Crontrol plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.1 when another vulnerability is present on the site that allows access to editing the database. This makes it possible for attackers to execute code on the server. Please see the advisory in references...
- CVSS:
- 7.5
- Affected:
- up to 1.16.1
- Fixed in:
- 1.16.2
- Disclosed:
- Mar 24, 2024
CVE-2024-28850 on NVD →
WP Crontrol < 1.3 - Reflected Cross-Site Scripting
medium
The WP Crontrol for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can su...
- CVSS:
- 6.1
- Affected:
- up to 1.3
- Fixed in:
- 1.3
- Disclosed:
- Aug 21, 2015
WP Crontrol [wp-crontrol] < 1.3 (closed)
unknown
Because of this vulnerability, authenticated administrators can store HTML and JS code.
Vulnerable parameters: "id[hookname]", "id[sig]", "id[next_run]", "id[args][code]".
Update the plugin.
- Affected:
- up to 1.3
- Fixed in:
- 1.3
- Disclosed:
- Aug 21, 2015
WP Crontrol [wp-crontrol] < 1.3 (closed)
unknown
The WP Crontrol for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can su...
- Affected:
- up to 1.3
- Fixed in:
- 1.3
- Disclosed:
- Aug 21, 2015
WP Crontrol [wp-crontrol] < 1.3 (closed)
unknown
The WP Crontrol WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 1.3
- Fixed in:
- 1.3
WP Crontrol [wp-crontrol] < 1.19.2
unknown
- Affected:
- up to 1.19.2
- Fixed in:
- 1.19.2
CVE-2025-8678 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database