WP-Recall – Registration, Profile, Commerce & More

Explore WP-Recall – Registration, Profile, Commerce & More vulnerabilities across all versions. Currently tracking 17 known vulnerabilities, including severity, impact, and patch status.

01234567891005.10.2021Today05.10.20216.1WP-Recall <= 16.24.47 - Reflected Cross-Site Scripting CVSS 6.1 · 05.10.202116.04.20244.3WP-Recall – Registration, Profile, Commerce & More <= 16.26.5 - Insecure Direct Object Reference CVSS 4.3 · 16.04.202422.04.20249.9WP-Recall – Registration, Profile, Commerce & More <= 16.26.5 - Authenticated (Contributor+) SQL Injection CVSS 9.9 · 22.04.202410.0WP-Recall – Registration, Profile, Commerce & More <= 16.26.5 - Unauthenticated SQL Injection CVSS 10.0 · 22.04.202403.06.20244.3WP-Recall <= 16.26.6 - Cross-Site Request Forgery CVSS 4.3 · 03.06.202405.06.20245.3WP-Recall – Registration, Profile, Commerce & More <= 16.26.6 - Unauthenticated Payment Deletion via delete_payment CVSS 5.3 · 05.06.202405.09.20249.8WP-Recall – Registration, Profile, Commerce & More <= 16.26.8 - Insecure Direct Object Reference to Unauthenticated Arbitrary Password Update CVSS 9.8 · 05.09.202403.03.20254.9WP-Recall – Registration, Profile, Commerce & More <= 16.26.11 - Authenticated (Admin+) SQL Injection CVSS 4.9 · 03.03.202507.03.20256.4WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CVSS 6.4 · 07.03.20254.3WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Authenticated (Contributor+) Protected Post Disclosure CVSS 4.3 · 07.03.20256.3WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Exeuction CVSS 6.3 · 07.03.20257.5WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Unauthenticated SQL Injection CVSS 7.5 · 07.03.202507.04.20254.4WP-Recall <= 16.26.11 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 07.04.202507.05.20258.8WP-Recall <= 16.26.14 - Authenticated (Contributor+) Local File Inclusion CVSS 8.8 · 07.05.202505.06.20254.3WP-Recall <= 16.26.14 - Cross-Site Request Forgery CVSS 4.3 · 05.06.202519.06.20255.3WP-Recall <= 16.26.14 - Missing Authorization CVSS 5.3 · 19.06.202526.06.20256.1WP-Recall <= 16.26.14 - Reflected Cross-Site Scripting CVSS 6.1 · 26.06.2025

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage76%
Open

4

Fixed

13

Get automatic notifications for all WP-Recall – Registration, Profile, Commerce & More vulnerabilities before they are exploited.

Vulnerability Records

17 records
2025-06-26 00:00CVE-2025-52796
6.1
Medium
Nguyen Xuan ChienNo
2025-06-19 00:00CVE-2025-49991
5.3
Medium
Nguyen Xuan ChienNo
2025-06-05 00:00CVE-2025-30981
4.3
Medium
0xd4rk5id3No
2025-05-07 00:00CVE-2025-47653
8.8
High
Muhammad Yudha - DJNo
2025-04-07 00:00CVE-2024-9771
4.4
Medium
Bob MatyasYes
2025-03-07 20:57CVE-2025-1323
7.5
High
Krzysztof ZającYes
2025-03-07 20:52CVE-2025-1325
6.3
Medium
Krzysztof ZającYes
2025-03-07 00:00CVE-2025-1324
6.4
Medium
Krzysztof ZającYes
2025-03-07 00:00CVE-2025-1322
4.3
Medium
Krzysztof ZającYes
2025-03-03 00:00CVE-2024-9770
4.9
Medium
y4ng0615Yes
Showing 1–10 of 17 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C