Impact
The vulnerability is a missing authorization flaw in the WPeMatico RSS Feed Fetcher plugin (etruel). It allows an attacker to bypass normal access restrictions and perform actions that should be limited to privileged users. This weakness is classified as CWE-862, meaning the plugin accepts requests from users who lack the necessary permissions.
Affected Systems
Affected software is the etruel WPeMatico RSS Feed Fetcher plugin for WordPress, versions from the earliest release up through 2.8.3. No other products or versions are listed, so any WordPress site using a vulnerable plugin installation is potentially impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, while the EPSS score of less than 1% shows low current exploitation likelihood. The vulnerability is not listed in CISA's KEV catalog. The attack vector is inferred to be web‑based, requiring the ability to send crafted requests to the plugin’s endpoints; no additional authentication appears to be needed, so the risk to any publicly accessible site is mainly limited to unauthorized modification or access to the RSS feed management interface.
OpenCVE Enrichment