Extendons WordPress and WooCommerce Scraper Plugin Server-Side Request Forgery Vulnerability

Vulnerability

A Server-Side Request Forgery (SSRF) vulnerability exists in the Extendons WordPress & WooCommerce Scraper Plugin, specifically in versions prior to and including 1.0.7. This vulnerability allows attackers to send crafted requests from the server where the plugin is installed, potentially leading to unauthorized access to internal resources or services.

Impact

Exploitation of this vulnerability allows for Server-Side Request Forgery, where an attacker can make the server send requests to internal or external resources, potentially leading to further exploitation or information disclosure.

Added: Dec 31, 2025, 5:22 PM
Updated: Dec 31, 2025, 9:15 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
0.0
relevance
1.7
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.