WP24 Domain Check
WP24 Domain Check has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2024; all 2 are fixed as of September 2026. Their average CVSS score is 5.8, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for WP24 Domain Check has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. WP24 Domain Check is installed on roughly 4,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-24602WP24 Domain Check <= 1.10.14 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records
WP24 Domain Check
Author
WP24
WP24 Domain Check allows users to check domains if they are free for registration. The responsive form could be easily integrated via shortcode or widget. Labels and colors are customizable through the settings page. Features Easy integration via shortcode or widget Ajax based search (no page reload required) Define a list of testable TLDs Drop-down list (select the TLD from predefined list) Free text input (type TLD into domain name field) Over 1,600 supported TLDs Add custom whois servers Possibility of checking every TLD Internationalized domain name (IDN) support Check all TLDs simultaneously (asynchronous) Show detailed whois information (if domain is registered) Provide price and purchase link for each TLD WooCommerce integration Responsive design Bot protection with Google reCAPTCHA or Cloudflare Turnstile Customization of labels and colors WPML and Polylang compatible
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C