Kunalnagar maintains a narrowly scoped product line centered on the Custom 404 Pro plugin, which despite a small footprint ranks among the more prominent vendors in the vulnerability landscape. Vulnerabilities affecting this product skew toward serious outcomes and frequently acquire public exploit code; the recurring weakness classes—cross-site scripting, cross-site request forgery, and SQL injection—reflect common application-layer input-handling and session-management flaws endemic to web-facing software. Current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kunalnagar over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2023MEDIUM The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting. | May 30, 2023 | 6.1 | 39 | NO | YES |
CVE-2019-14789MEDIUM The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter. | Aug 15, 2019 | 6.1 | 31 | NO | YES |
CVE-2023-2032CRITICAL The Custom 404 Pro WordPress plugin before 3.8.1 does not properly sanitize database inputs, leading to multiple SQL Injection vulnerabilities. | Jun 27, 2023 | 9.8 | 27 | NO | NO |
CVE-2024-39646MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kunal Custom 404 Pro custom-404-pro.This issue affects Custom 404 Pro: from n/ | Aug 1, 2024 | 6.1 | 24 | NO | YES |
CVE-2022-47605HIGH Auth. SQL Injection') vulnerability in Kunal Nagar Custom 404 Pro plugin <= 3.7.0 versions. | Apr 12, 2023 | 7.2 | 24 | NO | NO |
CVE-2019-15838MEDIUM The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789. | Aug 30, 2019 | 6.1 | 21 | NO | NO |
CVE-2023-32740MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kunal Nagar Custom 404 Pro plugin <= 3.8.1 versions. | Aug 30, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-51540MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kunal Nagar Custom 404 Pro allows Stored XSS.This issue affects Custom 404 Pro | Feb 1, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-0385MEDIUM The Custom 404 Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.1. This is due to missing or incorrect nonce validation on | Jan 18, 2023 | 4.3 | 18 | NO | NO |
CVE-2025-9947MEDIUM The Custom 404 Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘path’ parameter in all versions up to, and including, 3.12.0 due to insufficient escaping | Oct 11, 2025 | 4.9 | 17 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kunalnagar.
Media articles that mention a CVE ID that affects a product developed by Kunalnagar — matched by CVE ID, not by vendor name.