Uptime Robot Plugin for WordPress
Uptime Robot Plugin for WordPress has 3 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; none of them are fixed as of September 2026. Their average CVSS score is 5.7, and the most serious one scores 6.5 out of 10. 2025 was the busiest year with 3 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (33%). Other recurring categories include Cross-Site Scripting, SQL Injection.
None of the 3 issues recorded for Uptime Robot Plugin for WordPress have a published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
3 independent researchers contributed these findings, one record each. Uptime Robot Plugin for WordPress is installed on roughly 600 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.1.12.
CVE-2025-31547Uptime Robot Plugin for WordPress <= 2.3 - Authenticated (Contributor+) SQL Injection
Read the full analysisVulnerability Records

Uptime Robot Plugin for WordPress
Author
Aphotrax
This Uptime Robot Plugin for WordPress let’s you show your uptime server stats from Uptime Robot inside the WordPress admin area and if desired on pages, posts or in a widget. You can show multiple monitors on your preffered place using a simpel shortcode. Account at UptimeRobot.com required Simple installation and configuration Admin side Settings, choose wich monitors to be enabled, move offline monitors to the top View all monitors including status, duration and details Drag and drop to order monitors Logs with offline/paused status history Response time charts for all monitors Shortcode guide Custom caching time Client side Customize styling Display uptime stats anywhere with a shortcode [uptime-robot] Display logs where you want it with a shortcode [uptime-robot-logs] Display a response time chart where you want it with a shortcode [uptime-robot-response] Custom front end shortcodes (see shortcode page inside admin area). Check out the live demo @Aphotrax
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C