CodeRevolution Vulnerabilities and Affected Products
Vulnerabilities associated with Crawlomatic Multipage Scraper Post Generator.
Products
Clear product- Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit4 vulnerabilities
- Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit2 vulnerabilities
- Crawlomatic Multipage Scraper Post Generator2 vulnerabilities
- Crawlomatic Multisite Scraper Post Generator2 vulnerabilities
- Echo RSS Feed Post Generator2 vulnerabilities
- WP Pocket URLs2 vulnerabilities
- Aimogen Pro1 vulnerability
- Aiomatic1 vulnerability
- aiomatic-automatic_ai_content_writer_\&_editor1 vulnerability
- Demo My WordPress1 vulnerability
- demo_my_wordpress1 vulnerability
- Echo RSS Feed Post Generator Plugin for WordPress1 vulnerability
- echo_rss_feed_post_generator1 vulnerability
- WP Setup Wizard1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-9009HIGH | Crawlomatic Multipage Scraper Post Generator <= 2.7.2 - Authenticated (Author+) Remote Code Execution via 'callback_raw' Shortcode AttributeThe Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.7.2 via the filter_content function. This is due to passing the attacker-supplied 'callback_raw' shortcode attribute directly into call_user_func() with no sanitization or allowlist validation, relying solely on an is_callable() check that permits dangerous PHP built-ins such as system, shell_exec, exec, passthru, and assert. This makes it possible … CWE-434May 28, 2026 | CVSS8.8v3.1 | EPSS0.446% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-4389CRITICAL | Crawlomatic Multipage Scraper Post Generator <= 2.6.8.1 - Unauthenticated Arbitrary File UploadThe Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the crawlomatic_generate_featured_image() function in all versions up to, and including, 2.6.8.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. CWE-434May 17, 2025 | CVSS9.8v3.1 | EPSS0.936% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |