Impact
The vulnerability allows a user with the Contributor role or higher to import an RSS feed that contains malicious script. The plugin stores the feed content without sanitization, causing the script to be embedded in a post and executed in the browser of any visitor who views the post. This can enable attackers to steal session cookies, deface content, or perform other client‑side attacks. The weakness is an improper neutralization of input during web page generation, which can lead to loss of confidentiality, integrity, and availability of the affected website.
Affected Systems
WordPress sites using the WPeMatico RSS Feed Fetcher plugin, versions older than 2.8.27. Users who can upload or manage RSS feeds (Contributors and above) are able to trigger the attack.
Risk and Exploitability
The flaw requires attacker control over a feed import, which is achievable only by users with Contributor permissions. Once an exploit is launched, the script runs in the context of any visitor who views the stored post. No network‑level access or additional credentials are required beyond the Contributor role. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, but the potential impact of stored XSS in a widely used WordPress plugin warrants immediate attention. Users should assume that the vulnerability can be exercised by any site administrator with Contributor access.
OpenCVE Enrichment