CVE · High

CVE-2024-28850 — WP Crontrol [wp-crontrol] < 1.16.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-28850 WP Crontrol [wp-crontrol] < 1.16.2 Download of Code Without Integrity Check High 8.1 < 1.16.2 1.16.2 2024-03-24

CVE-2024-28850

WP Crontrol versions before 1.16.2 allow administrators to create WP-Cron events containing PHP code, which could potentially be exploited for remote code execution if combined with other vulnerabilities such as SQL injection, database compromise, unauthorized wp_options modifications, or arbitrary action/filter triggering. The plugin introduced integrity protections in version 1.16.2 to prevent unauthorized modification of stored PHP code in cron events as a security hardening measure.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.