Impact
The WPeMatico RSS Feed Fetcher plugin, prior to version 2.8.26, contains an authorization bypass that allows any user with contributor‑level or higher privileges to retrieve the configuration details and runtime logs of campaigns created by other users, including administrators. The flaw stems from inadequate ownership verification on the API route that serves campaign data, permitting read access across distinct user boundaries. Consequently, sensitive campaign settings and execution histories are exposed to users who should be unable to view them.
Affected Systems
Any WordPress site that has installed the WPeMatico RSS Feed Fetcher plugin in a version older than 2.8.26 is affected. The vendor information is listed as Unknown:WPeMatico RSS Feed Fetcher, so the impact extends to all installations regardless of the hosting environment.
Risk and Exploitability
The CVSS score of 2.7 indicates a low severity, and the EPSS score is 0.00147 (<1%), indicating a very low exploitation probability; the vulnerability is classified as an IDOR (Insecure Direct Object Reference). An attacker who has already obtained contributor or higher credentials can exploit the flaw simply by accessing the plugin’s standard endpoints. The lack of a KEV listing and absence of known public exploits suggest that the risk is low but still significant due to the potential for data leakage. The attack route is within normal plugin usage, so it does not require additional privileges beyond existing contributor‑level access.
OpenCVE Enrichment