Impact
The WPeMatico RSS Feed Fetcher plugin for WordPress before version 2.8.27 does not perform a capability check before fetching a user-supplied URL, allowing users with contributor-level access or higher to force the server to issue requests to internal-only hosts and read the responses back. This can be used to enumerate or exfiltrate data from internal services, potentially enabling further attacks.
Affected Systems
Affected products include the WPeMatico RSS Feed Fetcher WordPress plugin, versions prior to 2.8.27.
Risk and Exploitability
The vulnerability can be exploited through the campaign preview feature. An attacker with contributor privileges can supply a malicious URL that points to internal addresses; the plugin will fetch the content without validation. Although no remote code execution is directly granted, the ability to read internal host responses can lead to data leakage and facilitate advanced internal reconnaissance. The exploit is straightforward, does not require additional components, and the plugin’s lack of an authentication check makes it highly actionable. The absence of an EPSS score and its current status outside of the KEV catalogue do not diminish the inherent risk posed by the SSRF flaw.
OpenCVE Enrichment