WP Revisions Manager

WP Revisions Manager has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it remains unpatched as of August 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for WP Revisions Manager has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2024.

All of these findings were reported by Marek Mikita. WP Revisions Manager is installed on roughly 700 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.4.20.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all WP Revisions Manager vulnerabilities before they are exploited.

Most severe open issueCVSS 6.1CVE-2024-53761

WP Revisions Manager <= 1.0.2 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
WP Revisions Manager banner
Latestv1.0.2

WP Revisions Manager

P Roy

Author

P Roy

3.7(3)
74/100
Last Updated
2020-09-11 (6y ago)
Active Installs
700+
Downloads
6,481
Requires WP
4.5+
Requires PHP
0+
Tested up to
WP 5.4.20
Created
2019-04-01 (8y ago)

It helps you keep a clean database by removing unnecessary posts revisions. It lets you delete specific posts revisions. Perfectly integrated in the WordPress back-end, and uses wordpress core functions to safely delete revisions. You can also limit the number of revisions to be stored. How does it work? The plugin adds a discreet link next to the default revisions counter (see screen-shots section). When you click on it, it will purge the appropriate post revisions via AJAX. It also add a new bulk action option in the post/page row view to let you purge revisions of multiple posts at once. NOTE: Works only for the post_types that supports &#8216;revisions’

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C