CVE-2025-4389

CRITICAL

Crawlomatic Multipage Scraper Post Generator <2.6.8.1 - File Upload

Title source: llm

Description

The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the crawlomatic_generate_featured_image() function in all versions up to, and including, 2.6.8.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

Exploits (1)

nomisec WORKING POC
by Yucaerin · poc
https://github.com/Yucaerin/CVE-2025-4389

Scores

CVSS v3 9.8
EPSS 0.0256
EPSS Percentile 85.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
CodeRevolution/Crawlomatic Multipage Scraper Post Generator < 2.6.8.1
Published May 17, 2025
Tracked Since Feb 18, 2026