WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Custom 404 Pro

Take control of every 404 on your site — redirect visitors to a custom page or URL, log what broke, and get notified when it matters.

12Reported vulnerabilities
9.8Highest CVSS score
3.15.1Latest version
7,000+Active installs

What to do now

Update Custom 404 Pro to 3.12.1 or later. 11 of these have a fixed version available. Updating resolves them.

Plugin last updated: May 25, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2023-2032 Critical 9.8 0.9% Before 3.8.1 3.8.1 June 27, 2023
CVE-2023-2023 Medium 6.1 1.7% Before 3.7.3 3.7.3 May 30, 2023
CVE-2019-14789 Medium 6.1 1.6% 3.2.8 to 3.2.8 (inclusive) 3.2.9 August 15, 2019
WF-d22fb2e8-bb61-49bc-9fab-8f7c58339a69 Critical 9.8 Before 3.7.3 3.7.3 April 25, 2023
CVE-2023-51540 High 7.2 0.4% 3.10.0 and earlier 3.10.1 December 27, 2023
CVE-2022-47605 High 7.2 0.7% 3.7.0 and earlier 3.7.1 January 13, 2023
CVE-2024-39646 Medium 6.1 0.6% 3.11.1 and earlier 3.11.2 August 1, 2024
CVE-2019-15838 Medium 6.1 0.9% Before 3.2.8 3.2.8 August 30, 2019
CVE-2023-32740 Medium 6.1 0.3% 3.8.1 and earlier 3.8.2 May 15, 2023
CVE-2025-9947 Medium 4.9 0.3% 0 to 3.12.0 (inclusive) October 11, 2025
CVE-2025-62880 Medium 4.3 0.1% 3.12.0 and earlier 3.12.1 May 13, 2025
CVE-2023-0385 Medium 4.3 0.3% Before 3.7.2 3.7.2 January 18, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.