Impact
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destination of a user‑supplied feed URL when a campaign is executed. This omission allows a user with contributor-level or higher permissions to trigger the plugin’s server‑side fetch routine, causing the web server to retrieve arbitrary URLs of the attacker’s choosing. The attack yields a Server Side Request Forgery, enabling access to internal‑only resources or restricted endpoints and returning the fetched content back to the user, thereby compromising confidentiality and providing potential footholds for further exploitation.
Affected Systems
Only the WPeMatico RSS Feed Fetcher WordPress plugin is affected; versions earlier than 2.8.27 contain the flaw. The CNA does not list a formal vendor, but the product name is used in the plugin directory. Any WordPress installation that has this plugin and assigns contributor or higher roles is vulnerable.
Risk and Exploitability
EPSS information is not available and the flaw is not listed in the CISA KEV catalog, so publicly known exploitation campaigns have not been reported. The attack requires only contributor-level access, a role that many sites grant to content creators, and the attacker needs only to supply a malicious feed URL when running a campaign. By pointing the URL at internal addresses such as localhost or private network ranges, an attacker can bypass perimeter defenses and read sensitive data from within the organization. While the exploitation likelihood is uncertain, the potential impact on confidentiality is high for sites that expose contributor access to campaign functionality.
OpenCVE Enrichment