WordPress & WooCommerce Scraper Plugin, Import Data from Any WebSite. <= 1.0.7 - Unauthenticated Arbitrary File Upload
critical
The WordPress & WooCommerce Scraper Plugin, Import Data from Any WebSite. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.0.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's se...
- CVSS:
- 9.8
- Affected:
- up to 1.0.7
- Fix:
- No patched version reported
- Disclosed:
- Jun 12, 2026
CVE-2025-69129 on NVD →
WordPress & WooCommerce Scraper Plugin, Import Data from Any WebSite. <= 1.0.7 - Unauthenticated Arbitrary File Download
high
The WordPress & WooCommerce Scraper Plugin, Import Data from Any WebSite. plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0.7. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive informa...
- CVSS:
- 7.5
- Affected:
- up to 1.0.7
- Fix:
- No patched version reported
- Disclosed:
- Jun 12, 2026
CVE-2025-69131 on NVD →
WordPress & WooCommerce Scraper Plugin, Import Data from Any WebSite. <= 1.0.7 - Unauthenticated Server-Side Request Forgery
high
The WordPress & WooCommerce Scraper Plugin, Import Data from Any WebSite. plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.7. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application w...
- CVSS:
- 7.2
- Affected:
- up to 1.0.7
- Fix:
- No patched version reported
- Disclosed:
- Dec 31, 2025
CVE-2025-62088 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database