Server-Side Request Forgery in WordPress & WooCommerce Scraper Plugin by Extendons
CVE-2025-62088
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 31 December 2025
What is CVE-2025-62088?
A Server-Side Request Forgery (SSRF) vulnerability exists in the Extendons WordPress & WooCommerce Scraper Plugin. This vulnerability allows attackers to send crafted requests from the server, potentially exposing sensitive internal resources and leading to unauthorized actions on behalf of the system. Affected users should immediately review their installations, particularly versions from n/a through 1.0.7, to ensure their systems are protected from potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved