Impact
The WPeMatico RSS Feed Fetcher plugin fails to sanitize data retrieved from external RSS feeds before it is rendered. This omission allows a contributor to inject script code that is stored within the plugin’s internal data structures. When a higher-privileged user views the campaign preview, the malicious script executes in the user’s browser, enabling session hijacking, theft of cookies, or arbitrary code execution on the site. The vulnerable logic directly violates proper output encoding practices. The weakness aligns with CWE-79 and CWE-116.
Affected Systems
Any WordPress site that installs WPeMatico RSS Feed Fetcher version older than 2.8.26 and grants contributor or equivalent role access to campaign item creation. The vendor is listed as Unknown:WPeMatico RSS Feed Fetcher; the flaw is in all releases prior to the specified version.
Risk and Exploitability
Although EPSS data is not available and the vulnerability is not yet in the CISA KEV catalog, the CVSS base score for stored cross‑site scripting is typically high (8–10). Exploitation requires a contributor‑level user to submit a crafted RSS feed URL or payload; no network exposure is required beyond normal WordPress administrative access. The attack vector is local within the WordPress admin environment, but the impact extends to any user who views the compromised campaign. Given the ubiquity of WordPress and the potential for elevated privileges, the risk of exploitation remains significant.
OpenCVE Enrichment