SensorPress
SensorPress has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for SensorPress has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Nabil Irawan. SensorPress is installed on roughly 30 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 3.7.41.
CVE-2025-49409SensorPress <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records
SensorPress
Author
brewlabs
SensorPress brings simple uptime monitoring to the admin dashboard. Simple install the plugin add a few settings and your site will be checked every 15 minutes for FREE :). SensorPress is a complete uptime monitoring solution for any WordPress site all in a simple and easy to use plugin. Rather then attempting to provide every feature under the sun, SensorPress makes monitoring simple and complete by providing just the features you need. Some Features: Site checks at least every 15 minutes All managed from WordPress no account required Currently supports email notifications when sites go down Find out more at SensorPress.com.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C