Description
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returning a campaign's stored configuration and run log, allowing users with contributor-level access and above to read the configuration and execution logs of campaigns created by other users, including administrators.
Published: 2026-09-24
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Disclosure of Campaign Configuration and Execution Logs
Action: Immediate Patch
AI Analysis

Impact

The WPeMatico RSS Feed Fetcher plugin, prior to version 2.8.26, contains an authorization bypass that allows any user with contributor‑level or higher privileges to retrieve the configuration details and runtime logs of campaigns created by other users, including administrators. The flaw stems from inadequate ownership verification on the API route that serves campaign data, permitting read access across distinct user boundaries. Consequently, sensitive campaign settings and execution histories are exposed to users who should be unable to view them.

Affected Systems

Any WordPress site that has installed the WPeMatico RSS Feed Fetcher plugin in a version older than 2.8.26 is affected. The vendor information is listed as Unknown:WPeMatico RSS Feed Fetcher, so the impact extends to all installations regardless of the hosting environment.

Risk and Exploitability

The CVSS score of 2.7 indicates a low severity, and the EPSS score is 0.00147 (<1%), indicating a very low exploitation probability; the vulnerability is classified as an IDOR (Insecure Direct Object Reference). An attacker who has already obtained contributor or higher credentials can exploit the flaw simply by accessing the plugin’s standard endpoints. The lack of a KEV listing and absence of known public exploits suggest that the risk is low but still significant due to the potential for data leakage. The attack route is within normal plugin usage, so it does not require additional privileges beyond existing contributor‑level access.

Generated by OpenCVE AI on September 25, 2026 at 02:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WPeMatico RSS Feed Fetcher to version 2.8.26 or later.
  • Revoke or restrict contributor permissions on the WordPress site to limit unintended data exposure.
  • Apply the plugin’s log visibility setting to restrict log access to administrators only.

Generated by OpenCVE AI on September 25, 2026 at 02:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 24 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Thu, 24 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returning a campaign's stored configuration and run log, allowing users with contributor-level access and above to read the configuration and execution logs of campaigns created by other users, including administrators.
Title WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Campaign Configuration and Log Disclosure via IDOR
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-24T10:41:54.619Z

Reserved: 2026-09-10T16:19:31.946Z

Link: CVE-2026-89004

cve-icon Vulnrichment

Updated: 2026-09-24T10:33:45.783Z

cve-icon NVD

Status : Deferred

Published: 2026-09-24T06:17:03.740

Modified: 2026-09-24T14:42:02.707

Link: CVE-2026-89004

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T02:30:07Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key