Impact
The vulnerability is an unauthenticated Cross‑Site Scripting flaw in the WPeMatico RSS Feed Fetcher plugin up to version 2.8.17. From the description, an attacker can embed malicious JavaScript into RSS feeds that the plugin retrieves or into a URL that triggers its parsing logic. When an affected user views the compromised feed, the injected script executes in the visitor’s browser under the site’s context, allowing the attacker to inject arbitrary code into the page.
Affected Systems
The affected product is the WPeMatico RSS Feed Fetcher plugin developed by etruel, used in WordPress sites. All WordPress installations that have the plugin version 2.8.17 or older are vulnerable, while installations that have updated to version 2.8.18 or later are not affected.
Risk and Exploitability
The CVSS score of 7.1 reflects high severity risk. The EPSS score of <1% indicates a very low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is unauthenticated and can be triggered by delivering malicious content via the feed, the likely attack vector is public‑facing and requires only low effort. Based on the description, it is inferred that the exploit path involves embedding malicious scripts into RSS feeds or crafting URLs that exercise vulnerable parsing logic.
OpenCVE Enrichment