Description
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destination of a user-supplied feed URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to internal-only resources and read the responses back.
Published: 2026-09-27
Score: n/a
EPSS: n/a
KEV: No
Impact: Server Side Request Forgery
Action: Apply Patch
AI Analysis

Impact

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destination of a user‑supplied feed URL when a campaign is executed. This omission allows a user with contributor-level or higher permissions to trigger the plugin’s server‑side fetch routine, causing the web server to retrieve arbitrary URLs of the attacker’s choosing. The attack yields a Server Side Request Forgery, enabling access to internal‑only resources or restricted endpoints and returning the fetched content back to the user, thereby compromising confidentiality and providing potential footholds for further exploitation.

Affected Systems

Only the WPeMatico RSS Feed Fetcher WordPress plugin is affected; versions earlier than 2.8.27 contain the flaw. The CNA does not list a formal vendor, but the product name is used in the plugin directory. Any WordPress installation that has this plugin and assigns contributor or higher roles is vulnerable.

Risk and Exploitability

EPSS information is not available and the flaw is not listed in the CISA KEV catalog, so publicly known exploitation campaigns have not been reported. The attack requires only contributor-level access, a role that many sites grant to content creators, and the attacker needs only to supply a malicious feed URL when running a campaign. By pointing the URL at internal addresses such as localhost or private network ranges, an attacker can bypass perimeter defenses and read sensitive data from within the organization. While the exploitation likelihood is uncertain, the potential impact on confidentiality is high for sites that expose contributor access to campaign functionality.

Generated by OpenCVE AI on September 27, 2026 at 07:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WPeMatico RSS Feed Fetcher plugin to version 2.8.27 or later to resolve the missing capability check and URL validation.
  • If an immediate upgrade is not feasible, remove or rename the campaign functionality for contributor users or revoke contributor access to the plugin’s execution paths.
  • As a temporary protective measure, isolate the WordPress server from internal networks or block outbound requests to private IP ranges until the plugin can be updated or the access controls are tightened.

Generated by OpenCVE AI on September 27, 2026 at 07:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Sun, 27 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destination of a user-supplied feed URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to internal-only resources and read the responses back.
Title WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Run
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-27T06:00:20.905Z

Reserved: 2026-09-10T16:19:17.510Z

Link: CVE-2026-89000

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-27T06:17:19.283

Modified: 2026-09-27T06:17:19.283

Link: CVE-2026-89000

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T07:30:17Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)