Recursos /
Plugins de WordPress /
Wp Crontrol
SEGURIDAD DE PLUGINS
¿Es seguro Wp Crontrol?
Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Wp Crontrol — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
- Slug:
wp-crontrol
- 300000+ instalaciones activas
croncrontroldebugwoocommercewp cron
Estado de mantenimiento
- Última versión conocida: 1.21.0
- Requiere PHP: 7.4+
- PHP máximo soportado (analizado): 8.4
Vulnerabilidades conocidas
2 CVEs conocidos registrados para Wp Crontrol.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2024-28850
|
WP Crontrol [wp-crontrol] < 1.16.2 |
Descarga de código sin verificación de integridad |
Alta
8,1
|
< 1.16.2
|
1.16.2 |
2024-03-24 |
✓ corregido en la última versión
|
|
—
|
WP Crontrol [wp-crontrol] < 1.3 |
— |
Desconocido
|
< 1.3
|
1.3 |
2015-08-21 |
✓ corregido en la última versión
|
|
—
|
WP Crontrol [wp-crontrol] < 1.3 |
— |
Desconocido
|
< 1.3
|
1.3 |
2015-08-21 |
✓ corregido en la última versión
|
|
CVE-2025-8678
|
WP Crontrol [wp-crontrol] < 1.19.2 |
Falsificación de petición del lado del servidor (SSRF) |
Media
5,9
|
< 1.19.2
|
1.19.2 |
0000-00-00 |
✓ corregido en la última versión
|
|
—
|
WP Crontrol [wp-crontrol] < 1.3 |
— |
Desconocido
|
< 1.3
|
1.3 |
— |
✓ corregido en la última versión
|
CVE-2024-28850
WP Crontrol controls the cron events on WordPress websites. WP Crontrol includes a feature that allows administrative users to create events in the WP-Cron system that store and execute PHP code subject to the restrictive security permissions documented here. While there is no known vulnerability in this feature on its own, there exists potential for this feature to be vulnerable to RCE if it were specifically targeted via vulnerability chaining that exploited a separate SQLi (or similar) vulnerability. This is exploitable on a site if one of the below preconditions are met, the site is vulnerable to a writeable SQLi vulnerability in any plugin, theme, or WordPress core, the site's database is compromised at the hosting level, the site is vulnerable to a method of updating arbitrary options in the wp_options table, or the site is vulnerable to a method of triggering an arbitrary action, filter, or function with control of the parameters. As a hardening measure, WP Crontrol version 1.16.2 ships with a new feature that prevents tampering of the code stored in a PHP cron event.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
WP Crontrol [wp-crontrol] < 1.3
Because of this vulnerability, authenticated administrators can store HTML and JS code.
Vulnerable parameters: "id[hookname]", "id[sig]", "id[next_run]", "id[args][code]".
Update the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
WP Crontrol [wp-crontrol] < 1.3
The WP Crontrol for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-8678
The WP Crontrol plugin for WordPress is vulnerable to blind Server-Side Request Forgery in versions 1.17.0 to 1.19.1 via the 'wp_remote_request' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
WP Crontrol [wp-crontrol] < 1.3
The WP Crontrol WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Cómo solucionarlo
Mantén Wp Crontrol actualizado — 1.21.0 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas
Verifica tu propio sitio WordPress
Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.