Gravitate Automated Tester

Gravitate Automated Tester has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Gravitate Automated Tester has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.

All of these findings were reported by Vinit Lakra. Gravitate Automated Tester is installed on roughly 20 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.5.33.

Strategic Overview

Avg CVSSMedium
4.4/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all Gravitate Automated Tester vulnerabilities before they are exploited.

Most severe open issueCVSS 4.4CVE-2025-58645

Gravitate Automated Tester <= 1.4.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Gravitate Automated Tester banner
Latestv1.4.5

Gravitate Automated Tester

Gravitate

Author

Gravitate

5.0(1)
100/100
Last Updated
2016-06-24 (10y ago)
Active Installs
20+
Downloads
2,429
Requires WP
3.5+
Requires PHP
0+
Tested up to
WP 4.5.33
Created
2015-12-21 (11y ago)

Description: This Plugin allows you to easily run Tests against our PHP or JS code. It is mainly meant for Developers, but can be used by anyone. Like checking that you made sure that the site is indexable by Search Engines in Production and vise-versa that it is not Indexable in Dev or Staging. Pre-Installed Tests PHP Errors – Check for PHP Errors, Warnings and Notices. Gravity Forms Honeypot – Check to make sure that Anti-Spam Honeypot is enabled on all forms. Checks Sitespeed against Google Site Speed Insights Checks for Sitemap Pages Checks for Favicon HTML Valid – Check that your Pages are HTML Valid (W3C) JS Console Logs – Check General Pages for Console Logs on Page Load JS Errors – Check General Pages for JS Errors on Page Load Plugins Updated – Make sure WordPress Plugins are the Latest Stable Version SEO Indexable – Allow search engines to index the site in Production SEO Remove Indexing – Disallow search engines to index the site in Dev and Staging WP Debug – Make sure WordPress Debug is set to false WP Head/Footer – Check for wp_head() and wp_footer() WP Updated – Make sure WordPress is Latest Stable Version More to come soon Requirements jQuery WordPress 3.5 or above PHP 5.3+ PHP cUrl

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C