PT-2025-41684 · WordPress · Wp Scraper

Valatty

+1

·

Published

2025-10-11

·

Updated

2025-10-11

·

CVE-2025-9975

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP Scraper plugin for WordPress versions prior to 5.8.2
Description The WP Scraper plugin for WordPress is susceptible to Server-Side Request Forgery (SSRF) in versions up to and including 5.8.1. This flaw resides within the wp scraper extract content function and permits authenticated attackers possessing Administrator-level privileges or higher to initiate web requests to arbitrary locations from the web application. This capability can be leveraged to query and modify information from internal services. In Cloud environments, this issue enables the retrieval of metadata.
Recommendations Update the WP Scraper plugin to version 5.8.2 or later.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-9975

Affected Products

Wp Scraper