Junglewise Threat Intelligence

CVE-2025-69131: Extendons WordPress & WooCommerce Scraper Plugin arbitrary file download

CVE-2025-69131 · Severity: high · CVSS 7.5 · Published 2026-06-17

Executive brief

A vulnerability exists in the WordPress & WooCommerce Scraper Plugin, which is used to import data from external websites into a WordPress store. An attacker can exploit this flaw to download sensitive files from the web server without needing to log in. This could lead to the exposure of critical information, such as site configuration files, database credentials, and backups, potentially resulting in a full site takeover.

Technical details

The WordPress & WooCommerce Scraper Plugin (wp_scraper) suffers from an arbitrary file download vulnerability due to improper limitation of a pathname to a restricted directory (CWE-22). The flaw allows an unauthenticated remote attacker to use path traversal sequences to access and download sensitive files outside of the intended directory on the server. This is achieved by sending a specially crafted network request to the vulnerable component. Successful exploitation grants the attacker access to sensitive data such as wp-config.php, which contains database credentials. As of the advisory date, no official patch has been released, and users are advised to seek alternative mitigations or monitor for updates.

Affected products

  • extendons WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7

Timeline

  • 2025-10-19: other: Vulnerability reported by researcher
  • 2026-06-12: advisory: Patchstack advisory published
  • 2026-06-17: disclosed: NVD publication date

References

Related threats