Skip to main content

Threat intelligence

WordPress & WooCommerce Scraper Plugin, Import Data from Any WebSite. <= 1.0.7 - Unauthenticated Server-Side Request Forgery

CVE-2025-62088 · wp_scraper

Important: Seeing this vulnerability listed does not mean your website is affected. Exposure depends on whether you run Wp_scraper at a vulnerable version. How SiteRespond intelligence works

Vulnerability
WordPress & WooCommerce Scraper Plugin, Import Data from Any WebSite. <= 1.0.7 - Unauthenticated Server-Side Request Forgery
Affected software
wp_scraper(Plugin)
Affected versions
  • ≤ 1.0.7
Authentication
Unauthenticated
Vulnerability type
Other
Published
31 December 2025
CISA KEV
Not listed in CISA KEV at last catalog refresh
Impact
This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.
Source

Data imported from Wordfence Intelligence (advisory 6fb07b77-3d8a-42c6-b62b-9567226333c5). Methodology and redistribution notes

Check whether your installed version is affected

SiteRespond Defence matches your installed Wp_scraper version against this catalog when the Defence plugin is connected to your WordPress site.