Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

WP-Recall – Registration, Profile, Commerce & More Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 17 vulnerability records associated with WP-Recall – Registration, Profile, Commerce & More, published between 2021 and 2025.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

At a glance

Security Snapshot

17Total records
3Critical
2High
12Medium
0Low
0Informational
13Patched records
4Currently marked unpatched
2021-10-05First disclosure
2025-06-26Latest disclosure
16 of 17CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
202111 records
202466 records
20251010 records

Severity Breakdown

SeverityRecordsShare
Critical317.6%
High211.8%
Medium1270.6%

Vulnerability-Type Breakdown

Missing Authorization

5 records29.4%

First: 2024. Latest: 2025.

SQL Injection

5 records29.4%

First: 2024. Latest: 2025.

Cross-Site Scripting

3 records17.6%

First: 2021. Latest: 2025.

CSRF

2 records11.8%

First: 2024. Latest: 2025.

Information Disclosure

1 record5.9%

First: 2025. Latest: 2025.

Other

1 record5.9%

First: 2025. Latest: 2025.

Patch Status

Patched
13
Currently marked unpatched
4
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 16.26.12
  • 16.26.9
  • 16.26.7
  • 16.26.6
  • 16.24.48

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-16.26.14WP-Recall <= 16.26.14 - Reflected Cross-Site ScriptingJune 26, 2025Not suppliedMedium
*-16.26.14WP-Recall <= 16.26.14 - Missing AuthorizationJune 19, 2025Not suppliedMedium
*-16.26.14WP-Recall <= 16.26.14 - Cross-Site Request ForgeryJune 5, 2025Not suppliedMedium
*-16.26.14WP-Recall <= 16.26.14 - Authenticated (Contributor+) Local File InclusionMay 7, 2025Not suppliedHigh
*-16.26.11WP-Recall <= 16.26.11 - Authenticated (Admin+) Stored Cross-Site ScriptingApril 7, 202516.26.12Medium
*-16.26.10WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Unauthenticated SQL InjectionMarch 7, 202516.26.12High
*-16.26.10WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode ExeuctionMarch 7, 202516.26.12Medium
*-16.26.10WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Authenticated (Contributor+) Protected Post DisclosureMarch 7, 202516.26.12Medium
*-16.26.10WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeMarch 7, 202516.26.12Medium
*-16.26.11WP-Recall – Registration, Profile, Commerce & More <= 16.26.11 - Authenticated (Admin+) SQL InjectionMarch 3, 202516.26.12Medium
*-16.26.8WP-Recall – Registration, Profile, Commerce & More <= 16.26.8 - Insecure Direct Object Reference to Unauthenticated Arbitrary Password UpdateSeptember 5, 202416.26.9Critical
*-16.26.6WP-Recall – Registration, Profile, Commerce & More <= 16.26.6 - Unauthenticated Payment Deletion via delete_paymentJune 5, 202416.26.7Medium
*-16.26.6WP-Recall <= 16.26.6 - Cross-Site Request ForgeryJune 3, 202416.26.7Medium
*-16.26.5WP-Recall – Registration, Profile, Commerce & More <= 16.26.5 - Authenticated (Contributor+) SQL InjectionApril 22, 202416.26.6Critical
*-16.26.5WP-Recall – Registration, Profile, Commerce & More <= 16.26.5 - Unauthenticated SQL InjectionApril 22, 202416.26.6Critical
*-16.26.5WP-Recall – Registration, Profile, Commerce & More <= 16.26.5 - Insecure Direct Object ReferenceApril 16, 202416.26.6Medium
*-16.24.47WP-Recall <= 16.24.47 - Reflected Cross-Site ScriptingOctober 5, 202116.24.48Medium

Selected source records

Latest Records

MediumCVE-2025-52796

WP-Recall <= 16.26.14 - Reflected Cross-Site Scripting

Published: June 26, 2025

Affected versions
*-16.26.14
Patched versions
Not supplied
Original Wordfence record
MediumCVE-2025-49991

WP-Recall <= 16.26.14 - Missing Authorization

Published: June 19, 2025

Affected versions
*-16.26.14
Patched versions
Not supplied
Original Wordfence record
MediumCVE-2025-30981

WP-Recall <= 16.26.14 - Cross-Site Request Forgery

Published: June 5, 2025

Affected versions
*-16.26.14
Patched versions
Not supplied
Original Wordfence record
HighCVE-2025-47653

WP-Recall <= 16.26.14 - Authenticated (Contributor+) Local File Inclusion

Published: May 7, 2025

Affected versions
*-16.26.14
Patched versions
Not supplied
Original Wordfence record
MediumCVE-2024-9771

WP-Recall <= 16.26.11 - Authenticated (Admin+) Stored Cross-Site Scripting

Published: April 7, 2025

Affected versions
*-16.26.11
Patched versions
16.26.12
Original Wordfence record
HighCVE-2025-1323

WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Unauthenticated SQL Injection

Published: March 7, 2025

Affected versions
*-16.26.10
Patched versions
16.26.12
Original Wordfence record
MediumCVE-2025-1325

WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Exeuction

Published: March 7, 2025

Affected versions
*-16.26.10
Patched versions
16.26.12
Original Wordfence record
MediumCVE-2025-1324

WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Published: March 7, 2025

Affected versions
*-16.26.10
Patched versions
16.26.12
Original Wordfence record

Highest-Severity Records

CriticalCVE-2024-32709

WP-Recall – Registration, Profile, Commerce & More <= 16.26.5 - Unauthenticated SQL Injection

Published: April 22, 2024

Affected versions
*-16.26.5
Patched versions
16.26.6
Original Wordfence record
CriticalCVE-2024-32710

WP-Recall – Registration, Profile, Commerce & More <= 16.26.5 - Authenticated (Contributor+) SQL Injection

Published: April 22, 2024

Affected versions
*-16.26.5
Patched versions
16.26.6
Original Wordfence record
CriticalCVE-2024-8292

WP-Recall – Registration, Profile, Commerce & More <= 16.26.8 - Insecure Direct Object Reference to Unauthenticated Arbitrary Password Update

Published: September 5, 2024

Affected versions
*-16.26.8
Patched versions
16.26.9
Original Wordfence record
HighCVE-2025-47653

WP-Recall <= 16.26.14 - Authenticated (Contributor+) Local File Inclusion

Published: May 7, 2025

Affected versions
*-16.26.14
Patched versions
Not supplied
Original Wordfence record
HighCVE-2025-1323

WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Unauthenticated SQL Injection

Published: March 7, 2025

Affected versions
*-16.26.10
Patched versions
16.26.12
Original Wordfence record
MediumCVE-2025-1324

WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Published: March 7, 2025

Affected versions
*-16.26.10
Patched versions
16.26.12
Original Wordfence record
MediumCVE-2025-1325

WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Exeuction

Published: March 7, 2025

Affected versions
*-16.26.10
Patched versions
16.26.12
Original Wordfence record
MediumCVE-2025-52796

WP-Recall <= 16.26.14 - Reflected Cross-Site Scripting

Published: June 26, 2025

Affected versions
*-16.26.14
Patched versions
Not supplied
Original Wordfence record

Currently Marked Unpatched Records

MediumCVE-2025-52796

WP-Recall <= 16.26.14 - Reflected Cross-Site Scripting

Published: June 26, 2025

Affected versions
*-16.26.14
Patched versions
Not supplied
Original Wordfence record
MediumCVE-2025-49991

WP-Recall <= 16.26.14 - Missing Authorization

Published: June 19, 2025

Affected versions
*-16.26.14
Patched versions
Not supplied
Original Wordfence record
MediumCVE-2025-30981

WP-Recall <= 16.26.14 - Cross-Site Request Forgery

Published: June 5, 2025

Affected versions
*-16.26.14
Patched versions
Not supplied
Original Wordfence record
HighCVE-2025-47653

WP-Recall <= 16.26.14 - Authenticated (Contributor+) Local File Inclusion

Published: May 7, 2025

Affected versions
*-16.26.14
Patched versions
Not supplied
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory