The Catalog Importer, Scraper & Crawler plugin for WordPress is vulnerable to PHP code injection in all versions up to, and including, 5.1.4. This is due to reliance on a guessable numeric token (e.g. ?key= 900001705) without proper authentication, combined with the unsafe use of eval() on user-supplied input. This makes it possible for unauthenticated attackers to execute arbitrary PHP code on the server via a forged request granted they can guess or brute-force the numeric key.
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 12 Sep 2025 08:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Wordpress
         Wordpress wordpress  | 
|
| Vendors & Products | 
        
        Wordpress
         Wordpress wordpress  | 
Thu, 11 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Thu, 11 Sep 2025 07:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | The Catalog Importer, Scraper & Crawler plugin for WordPress is vulnerable to PHP code injection in all versions up to, and including, 5.1.4. This is due to reliance on a guessable numeric token (e.g. ?key= 900001705) without proper authentication, combined with the unsafe use of eval() on user-supplied input. This makes it possible for unauthenticated attackers to execute arbitrary PHP code on the server via a forged request granted they can guess or brute-force the numeric key. | |
| Title | Catalog Importer, Scraper & Crawler <= 5.1.4 - Unauthenticated PHP Code Injection | |
| Weaknesses | CWE-94 | |
| References | 
         | 
        
  | 
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-09-11T07:24:52.519Z
Updated: 2025-09-11T14:40:32.368Z
Reserved: 2025-07-31T14:18:46.597Z
Link: CVE-2025-8417
Updated: 2025-09-11T14:06:16.239Z
Status : Awaiting Analysis
Published: 2025-09-11T08:15:33.680
Modified: 2025-09-11T17:14:10.147
Link: CVE-2025-8417
No data.