Description
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configuration fields when a certain feature is enabled, which allows users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the session of any higher-privileged user who later views the campaign.
Published: 2026-09-24
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

The vulnerability affects the WPeMatico RSS Feed Fetcher WordPress plugin before version 2.8.26. A campaign configuration field fails to be properly sanitised and escaped when a specific feature is enabled. Users with the Contributor role or higher can supply malicious content that is then stored and executed when a higher‑privileged user views the campaign. This allows an attacker to run arbitrary JavaScript in the victim’s browser, potentially stealing session cookies, credentials, or performing unwanted actions on the victim’s behalf.

Affected Systems

All WordPress installations that have the WPeMatico RSS Feed Fetcher plugin installed with a version earlier than 2.8.26. The vulnerability is present in the plugin itself and does not depend on other components, but any site that uses the feature enabling the vulnerable field is at risk.

Risk and Exploitability

The flaw is a stored cross‑site scripting that requires the attacker to have Contributor or higher access on the WordPress site. Once an attacker supplies the malicious payload, the execution occurs in the context of any higher‑privileged user who subsequently views the affected campaign. No publicly available exploit has been disclosed and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. The CVSS base score is 6.8, indicating a moderate severity that highlights potential impact on confidentiality, integrity, and availability for administrators and editors.

Generated by OpenCVE AI on September 24, 2026 at 12:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WPeMatico RSS Feed Fetcher plugin to version 2.8.26 or newer.
  • If an upgrade is not immediately possible, disable or remove the feature that allows the vulnerable campaign configuration field from being stored.
  • Audit the site for any stored XSS payloads that may have been left in existing campaigns and clean or delete them.

Generated by OpenCVE AI on September 24, 2026 at 12:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configuration fields when a certain feature is enabled, which allows users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the session of any higher-privileged user who later views the campaign.
Title WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Word to Category
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-24T10:41:54.496Z

Reserved: 2026-09-10T16:19:35.685Z

Link: CVE-2026-89005

cve-icon Vulnrichment

Updated: 2026-09-24T10:33:35.843Z

cve-icon NVD

Status : Deferred

Published: 2026-09-24T06:17:03.843

Modified: 2026-09-24T14:42:02.707

Link: CVE-2026-89005

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T12:45:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')