Cron Logger
Cron Logger has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Cron Logger has a vendor fix available, so running the current release closes it.
All of these findings were reported by Nguyen Xuan Chien. Cron Logger is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-53266Cron Logger <= 1.3.3 - Missing Authorization
Read the full analysisVulnerability Records

Cron Logger
Author
EdwardBock
Have you ever wondered what you WordPress is doing in wp-cron.php? Now you can see it. This plugin logs every schedule. Arbitrary section
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C