WP Revisions Manager
WP Revisions Manager has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it remains unpatched as of August 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for WP Revisions Manager has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2024.
All of these findings were reported by Marek Mikita. WP Revisions Manager is installed on roughly 700 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.4.20.
CVE-2024-53761WP Revisions Manager <= 1.0.2 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

WP Revisions Manager
Author
P Roy
It helps you keep a clean database by removing unnecessary posts revisions. It lets you delete specific posts revisions. Perfectly integrated in the WordPress back-end, and uses wordpress core functions to safely delete revisions. You can also limit the number of revisions to be stored. How does it work? The plugin adds a discreet link next to the default revisions counter (see screen-shots section). When you click on it, it will purge the appropriate post revisions via AJAX. It also add a new bulk action option in the post/page row view to let you purge revisions of multiple posts at once. NOTE: Works only for the post_types that supports ‘revisions’
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C