CVE-2025-62088: WordPress WordPress & WooCommerce Scraper plugin, Import Data from Any Site plugin <= 1.0.7 - Server Side Request Forgery (SSRF) vulnerability
Server-Side Request Forgery (SSRF) vulnerability in extendons WordPress & WooCommerce Scraper Plugin, Import Data from Any Site wpscraper allows Server Side Request Forgery.This issue affects WordPress & WooCommerce Scraper Plugin, Import Data from Any Site: from n/a through <= 1.0.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62088?
CVE-2025-62088 is classified as a high severity Server-Side Request Forgery (SSRF) vulnerability in the affected plugin.
How do I fix CVE-2025-62088?
To mitigate CVE-2025-62088, update the WordPress & WooCommerce Scraper Plugin to the latest version beyond 1.0.7.
What versions of the plugin are affected by CVE-2025-62088?
CVE-2025-62088 affects all versions of the WordPress & WooCommerce Scraper Plugin up to and including version 1.0.7.
What are the implications of CVE-2025-62088?
Exploitation of CVE-2025-62088 can allow attackers to send unauthorized requests from the server, potentially accessing sensitive internal resources.
Is my website vulnerable to CVE-2025-62088 if I use the plugin?
If you are using the WordPress & WooCommerce Scraper Plugin version 1.0.7 or earlier, your website is vulnerable to CVE-2025-62088.