Custom 404 Pro
Custom 404 Pro has 12 disclosed vulnerabilities in the WordSec catalog, reported between 2019 and 2025; 11 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 9.8 out of 10. Severity breakdown: 2 critical and 2 high. 2023 was the busiest year with 7 disclosures.
The most common weakness is Cross-Site Scripting, behind 6 of the records (50%). Other recurring categories include SQL Injection, Cross-Site Request Forgery (CSRF).
11 of the records (92%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.
9 independent researchers contributed these findings, one record each. Custom 404 Pro is installed on roughly 7,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-9947Custom 404 Pro <= 3.12.0 - Authenticated (Administrator+) SQL Injection via `path` Parameter
Read the full analysisVulnerability Records

Custom 404 Pro
Author
Kunal
Custom 404 Pro replaces WordPress’s default 404 behaviour with a proper redirect. Instead of leaving visitors on a dead-end error page, you can send them to any page on your site or an external URL — with the HTTP status code of your choice. Redirect Modes WordPress Page — pick any published page from a dropdown; the plugin redirects to it automatically. Custom URL — enter any absolute URL to redirect 404s off-site or to a specific path. HTTP Status Code — choose 301, 302, 307, or 308 to match your SEO or caching requirements. 404 Logging When logging is enabled, the plugin records every 404 hit to a database table so you can see exactly what is broken: Request path Visitor IP address (can be disabled for privacy/GDPR compliance) Referrer URL User agent Timestamp Logs are searchable and can be deleted individually, in bulk, or all at once. They can also be exported as a CSV file. A configurable retention policy lets you automatically cap the table by row count, by age, or both — with a daily background cleanup and an on-demand Prune Now button. Email Notifications Optionally receive an admin email each time a 404 is logged. Designed for low-traffic monitoring — if you expect high 404 volume, keep this off to avoid inbox flooding. Multisite Support Works correctly on WordPress Multisite installations — activation creates the logs table for each site in the network. Multilingual Support Compatible with Polylang and WPML. The redirect page is resolved to the correct language variant for the current visitor automatically.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C