PT-2025-37127 · WordPress · Catalog Importer

Alexander Chikaylo

·

Published

2025-09-11

·

Updated

2025-09-16

·

CVE-2025-8417

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Catalog Importer, Scraper & Crawler plugin for WordPress versions through 5.1.4
Description The Catalog Importer, Scraper & Crawler plugin for WordPress is susceptible to PHP code injection due to reliance on a guessable numeric token (e.g., ?key= 900001705) without proper authentication, combined with the unsafe use of the eval() function on user-supplied input. This allows unauthenticated attackers to execute arbitrary PHP code on the server via a forged request if they can guess or brute-force the numeric key.
Recommendations Versions prior to 5.1.5 are affected. Update to a version later than 5.1.4.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-8417

Affected Products

Catalog Importer