Extension WordPress

Vulnérabilités Crawlomatic Multipage Scraper Post Generator

Cette page rassemble les failles publiées pour Crawlomatic Multipage Scraper Post Generator, leurs plages de versions affectées et les correctifs signalés dans la base locale.

4Vulnérabilités
1Critiques
4Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Crawlomatic Multipage Scraper Post Generator

4 fiches

CVE-2026-9009 Élevée · 8,8
Crawlomatic Multipage Scraper Post Generator

Crawlomatic Multipage Scraper Post Generator <= 2.7.2 – Authenticated (Author+) Remote Code Execution via 'callback_raw' Shortcode Attribute

The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.7.2 via the filter_content function. This is due to passing the attacker-supplied 'callback_raw' shortcode attribute directly…

Versions affectées

*-2.7.2

Correctif

2.7.3

Publication

27/05/2026

CVE-2025-49294 Moyenne · 5,3
Crawlomatic Multipage Scraper Post Generator

Crawlomatic Multisite Scraper Post Generator <= 2.6.8.2 – Unauthenticated Information Exposure via Log Files

The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.8.2. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

Versions affectées

*-2.6.8.2

Correctif

2.6.9

Publication

05/06/2025

CVE-2025-49293 Moyenne · 4,3
Crawlomatic Multipage Scraper Post Generator

Crawlomatic Multisite Scraper Post Generator <= 2.6.8.2 – Missing Authorization

The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.6.8.2. This makes it possible for authenticated attackers,…

Versions affectées

*-2.6.8.2

Correctif

2.6.9

Publication

05/06/2025

CVE-2025-4389 Critique · 9,8
Crawlomatic Multipage Scraper Post Generator

Crawlomatic Multipage Scraper Post Generator <= 2.6.8.1 – Unauthenticated Arbitrary File Upload

The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the crawlomatic_generate_featured_image() function in all versions up to, and including, 2.6.8.1. This makes it possible for…

Versions affectées

*-2.6.8.1

Correctif

2.6.8.2

Publication

16/05/2025

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités