Catalog Importer, Scraper & Crawler <= 5.1.4 - Unauthenticated PHP Code Injection
high
The Catalog Importer, Scraper & Crawler plugin for WordPress is vulnerable to PHP code injection in all versions up to, and including, 5.1.4. This is due to reliance on a guessable numeric token (e.g. ?key= 900001705) without proper authentication, combined with the unsafe use of eval() on user-supplied input. This mak...
- CVSS:
- 8.1
- Affected:
- up to 5.1.4
- Fix:
- No patched version reported
- Disclosed:
- Sep 10, 2025
CVE-2025-8417 on NVD →
Catalog Importer, Scraper & Crawler [intelligent-importer] < 5.1.4 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in idIA Tech Catalog Importer, Scraper & Crawler allows Reflected XSS.This issue affects Catalog Importer, Scraper & Crawler: from n/a through 5.1.3.
- Affected:
- up to 5.1.4
- Fixed in:
- 5.1.4
- Disclosed:
- Feb 3, 2025
CVE-2025-22775 on NVD →
Catalog Importer, Scraper & Crawler <= 5.1.3 - Reflected Cross-Site Scripting
medium
The Catalog Importer, Scraper & Crawler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 5.1.3
- Fixed in:
- 5.1.4
- Disclosed:
- Jan 14, 2025
CVE-2025-22775 on NVD →
Catalog Importer, Scraper & Crawler [intelligent-importer] <= 5.1.4 (unfixed)
unknown
- Affected:
- up to 5.1.4
- Fix:
- No patched version reported
CVE-2025-8417 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database