CVE-2025-49294: WordPress Crawlomatic Multisite Scraper Post Generator plugin <= 2.6.8.2 - Sensitive Data Exposure via Log Exposure vulnerability
Insertion of Sensitive Information Into Sent Data vulnerability in CodeRevolution Crawlomatic Multisite Scraper Post Generator allows Retrieve Embedded Sensitive Data. This issue affects Crawlomatic Multisite Scraper Post Generator: from n/a through 2.6.8.2.
Other sources
Insertion of Sensitive Information Into Sent Data vulnerability in CodeRevolution Crawlomatic Multisite Scraper Post Generator crawlomatic-multipage-scraper-post-generator allows Retrieve Embedded Sensitive Data.This issue affects Crawlomatic Multisite Scraper Post Generator: from n/a through <= 2.6.8.2.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49294?
CVE-2025-49294 has a medium severity due to its potential for sensitive data exposure.
How do I fix CVE-2025-49294?
To fix CVE-2025-49294, upgrade the Crawlomatic Multisite Scraper Post Generator to the latest version beyond 2.6.8.2.
What types of data are affected by CVE-2025-49294?
CVE-2025-49294 can result in the unauthorized retrieval of embedded sensitive data.
Who is affected by CVE-2025-49294?
Users of CodeRevolution Crawlomatic Multisite Scraper Post Generator versions up to 2.6.8.2 are affected by CVE-2025-49294.
Is CVE-2025-49294 a remote code execution vulnerability?
No, CVE-2025-49294 is not a remote code execution vulnerability; it is related to data exposure.