WordPress Catalog Importer, Scraper & Crawler Unauthenticated PHP Code Injection Vulnerability

Vulnerability

A PHP code injection vulnerability has been identified in the Catalog Importer, Scraper & Crawler plugin for WordPress, affecting all versions through 5.1.4. The vulnerability arises from the plugin's reliance on a guessable numeric token, which lacks proper authentication, and the unsafe use of the eval() function on user-supplied input. This combination allows unauthenticated attackers to execute arbitrary PHP code on the server by sending a forged request with a guessed or brute-forced numeric key.

Impact

Exploitation of this vulnerability allows for arbitrary PHP code execution on the server where the affected WordPress site is hosted.

Reproduction

To reproduce this vulnerability, send a request to the WordPress site with the 'megaimporter_communication' parameter set to '1' and the 'clef' parameter containing a guessed numeric key. The 'codeGroovy', 'codeLiens', and 'codeFinal' parameters can also be included to demonstrate the injection of PHP code, which will be executed on the server.

Added: Sep 11, 2025, 8:25 AM
Updated: Sep 11, 2025, 8:25 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.4
remediation
0.0
relevance
0.5
threat
4.8
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.