Executive brief
The WordPress & WooCommerce Scraper plugin, which is used to import data from external websites into a store, contains a critical security flaw. This vulnerability allows an unauthenticated attacker to upload malicious files directly to the web server. Successful exploitation could lead to a total takeover of the website, allowing attackers to steal customer data, deface the site, or install backdoors for persistent access.
Technical details
The WordPress & WooCommerce Scraper Plugin, Import Data from Any Site (versions 1.0.7 and below) suffers from an Unrestricted Upload of File with Dangerous Type (CWE-434). The vulnerability allows a remote, unauthenticated attacker to upload arbitrary files, such as PHP scripts, to the server due to insufficient validation of uploaded content. Because no authentication is required and the attack vector is over the network, this flaw carries a CVSS score of 10.0. Attackers can achieve remote code execution (RCE) by accessing the uploaded files, leading to a complete compromise of the host's integrity, confidentiality, and availability. As of the advisory date, no official patch has been released.
Affected products
- Extendons WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7
Timeline
- 2025-10-16: other: Vulnerability reported by Denver Jackson
- 2026-06-12: advisory: Patchstack published advisory details
- 2026-06-17: disclosed: CVE published to NVD