
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62088 is a Server-Side Request Forgery (SSRF) vulnerability in the "WordPress & WooCommerce Scraper Plugin, Import Data from Any Site" (plugin slug: wp_scraper) developed by extendons. It affects all versions of the plugin through and including 1.0.7, allowing unauthenticated network attackers to forge server-side requests to arbitrary domains. The vulnerability was reported by security researcher "Bonds" on October 19, 2025, and publicly disclosed by Patchstack on December 31, 2025. It carries a CVSS v3.1 base score of 5.4 (Medium), assigned by Patchstack (Patchstack).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery), meaning the plugin fails to properly validate or restrict URLs supplied by user input before making server-side HTTP requests (Patchstack). Because the plugin's core function is to scrape and import data from external URLs, an attacker can supply a crafted URL pointing to internal network resources (e.g., http://169.254.169.254/ for cloud metadata, or internal services) and the server will fetch and potentially expose the response. Exploitation requires no authentication and no user interaction, though attack complexity is rated High, suggesting some precondition or bypass is needed (e.g., specific request construction). No public proof-of-concept code has been identified at this time.
Successful exploitation allows an attacker to cause the WordPress server to issue HTTP requests to arbitrary internal or external destinations, potentially exposing sensitive data from internal services, cloud metadata endpoints, or other backend systems not intended to be publicly accessible (Patchstack). The CVSS scope is rated "Changed," indicating the impact extends beyond the vulnerable component itself to other systems on the internal network. Confidentiality and integrity are both rated Low impact, with no availability impact; however, in cloud-hosted environments, SSRF can lead to credential theft via metadata services, enabling further lateral movement.
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-62088 as of the available data. The EPSS score is approximately 0.027% (0.000270), indicating a very low probability of exploitation in the near term (Feedly). Patchstack classifies this as "Low" priority and notes it is "unlikely to be exploited," though they also note that SSRF vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress plugins at scale (Patchstack). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been identified.
wp_scraper plugin (version ≤ 1.0.7) using tools like WPScan, Shodan, or by checking publicly accessible plugin metadata at https://target.com/wp-content/plugins/wp_scraper/readme.txt.http://169.254.169.254/latest/meta-data/ (AWS metadata), http://localhost/, or an attacker-controlled server to confirm outbound connectivity.10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) or cloud metadata endpoints (169.254.169.254); unexpected outbound connections to attacker-controlled external hosts originating from the web server process.wp_scraper plugin's AJAX or scraping endpoint with unusual or internal URL values in parameters; PHP error logs showing failed connection attempts to internal hosts.apache2, nginx, php-fpm) initiating outbound TCP connections to non-standard internal addresses or cloud metadata IPs.As of the disclosure date (December 31, 2025), Patchstack indicated no official patch was available from the plugin developer (extendons), and the patched version field was listed as "No official patch available" (Patchstack). However, Feedly intelligence notes that a patch is available in version 1.0.8 and later (Feedly). Administrators should update the plugin to version 1.0.8 or later if available; if no update is available, deactivating or removing the plugin is the recommended workaround. Additionally, deploying a Web Application Firewall (WAF) with SSRF detection rules and restricting outbound HTTP requests from the server at the network level can reduce risk.
Wordfence included CVE-2025-62088 in their weekly WordPress vulnerability report covering December 15, 2025 to January 4, 2026, providing broader community visibility (Wordfence). No significant independent researcher commentary, vendor statements beyond Patchstack's disclosure, or notable media coverage has been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."