CVE-2025-69131
Deferred Deferred - Pending Action
Unauthenticated Arbitrary File Download in WordPress Scraper Plugin

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Patchstack

Description
Unauthenticated Arbitrary File Download in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 versions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
patchstack wordpress_woocommerce_scraper_plugin_import_data_from_any_site to 1.0.8 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The vulnerability exists in the WordPress & WooCommerce Scraper Plugin, Import Data from Any Site Plugin, versions 1.0.7 and below.

It is an unauthenticated arbitrary file download issue, meaning attackers do not need to be logged in to exploit it.

This flaw allows attackers to download any file from the affected website, potentially exposing sensitive information.

Impact Analysis

Exploitation of this vulnerability can lead to unauthorized access to sensitive files on the website.

  • Attackers may obtain login credentials.
  • Backup files and other confidential data could be exposed.

This can result in data breaches, loss of trust, and potential further compromise of the website.

Detection Guidance

The vulnerability allows unauthenticated attackers to download arbitrary files from the affected website by exploiting the WordPress & WooCommerce Scraper Plugin, Import Data from Any Site Plugin versions 1.0.7 and below.

Detection can involve monitoring web server logs for unusual HTTP requests that attempt to access sensitive files or paths through the plugin's endpoints.

Specific commands are not provided in the available resources, but typical approaches include using tools like curl or wget to test for arbitrary file download by requesting known sensitive files via the plugin's URL patterns.

Mitigation Strategies

Immediate mitigation steps include applying the Patchstack mitigation rule designed to block attacks exploiting this vulnerability until an official patch is released.

It is also advised to update the plugin if a newer, fixed version becomes available.

If updating is not possible, seek assistance from your hosting provider or a web developer to implement temporary protections.

Compliance Impact

The vulnerability allows unauthenticated attackers to download any file from the affected website, potentially exposing sensitive data such as login credentials or backup files.

Exposure of sensitive data can lead to non-compliance with data protection regulations like GDPR and HIPAA, which require safeguarding personal and sensitive information against unauthorized access.

Therefore, this vulnerability poses a significant risk to compliance with such standards by potentially enabling data breaches.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-69131. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart