Impact
The vulnerability affects the WPeMatico RSS Feed Fetcher WordPress plugin before version 2.8.26. A campaign configuration field fails to be properly sanitised and escaped when a specific feature is enabled. Users with the Contributor role or higher can supply malicious content that is then stored and executed when a higher‑privileged user views the campaign. This allows an attacker to run arbitrary JavaScript in the victim’s browser, potentially stealing session cookies, credentials, or performing unwanted actions on the victim’s behalf.
Affected Systems
All WordPress installations that have the WPeMatico RSS Feed Fetcher plugin installed with a version earlier than 2.8.26. The vulnerability is present in the plugin itself and does not depend on other components, but any site that uses the feature enabling the vulnerable field is at risk.
Risk and Exploitability
The flaw is a stored cross‑site scripting that requires the attacker to have Contributor or higher access on the WordPress site. Once an attacker supplies the malicious payload, the execution occurs in the context of any higher‑privileged user who subsequently views the affected campaign. No publicly available exploit has been disclosed and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. The CVSS base score is 6.8, indicating a moderate severity that highlights potential impact on confidentiality, integrity, and availability for administrators and editors.
OpenCVE Enrichment