Impact
The vulnerability in the WPeMatico RSS Feed Fetcher plugin arises from a missing capability check in the wpematico_import_settings function. This flaw allows any authenticated user with a Subscriber role or higher to update arbitrary WordPress options, including the default user role and registration settings. By setting the default role to administrator and enabling user registration, the attacker can create or modify accounts that receive administrative privileges, effectively taking full control of the WordPress site.
Affected Systems
All WordPress installations using the WPeMatico RSS Feed Fetcher plugin version 2.8.24 or earlier are affected. The plugin is developed by the vendor etruel. Any site that has the plugin installed and where a user has Subscriber or higher access can exploit the flaw.
Risk and Exploitability
The vulnerability is scored with a CVSS base of 8.8, indicating high severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Attackers must be authenticated, but Subscriber-level access is sufficient to launch the attack. Given the high CVSS and the ease of exploitation via a standard WordPress login, the risk remains significant, although no publicly known exploits have been reported yet.
OpenCVE Enrichment