WPeMatico RSS Feed Fetcher WordPress 插件在 2.8.27 版本之前,未验证运行Feed活动的用户是否有权发布内容或将文章归因于其他账户,导致具有贡献者级(contributor)及以上权限的用户能够直接发布文章,并将任何已注册用户(包括管理员)设置为文章作者。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WPeMatico RSS Feed Fetcher | 0 ~ 2.8.27 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89006 | WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Stored XSS via Feed Import | |
| CVE-2026-84069 | WebFacing Email Accounts for cPanel 5.3 - 5.3.6 - Unauthenticated LFI via assets/index.php | |
| CVE-2026-81655 | Ad Inserter 2.8.12 - 2.8.18 - Subscriber+ RCE / Stored XSS via Global Custom Fields | |
| CVE-2026-82841 | UpdraftPlus 1.23.8 - 1.26.7 - Subscriber+ Remote Storage Credential Disclosure via Migrati | |
| CVE-2026-85002 | EmbedPress < 4.6.7 - Contributor+ Stored XSS via Instagram Carousel Block Attributes | |
| CVE-2026-86609 | Download Manager Pro < 7.5.6 - Unauthenticated Stored XSS via Email Lock Subscription | |
| CVE-2026-86839 | Bookly < 28.3 - Staff+ Appointment and Payment Disclosure, Modification and Deletion via I | |
| CVE-2026-86841 | Bookly 23.2 - 28.2 - Bookly Administrator+ PHP Object Injection via Diagnostics Advanced O | |
| CVE-2026-89003 | WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Preview | |
| CVE-2026-96899 | Optima Express 8.6.0 - 8.7.5 - Author+ Stored XSS via faq_script | |
| CVE-2026-89000 | WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Run | |
| CVE-2026-96896 | Malcure Malware Shield < 19.9.7 - Multisite Subsite Admin+ Arbitrary File Write and Deleti | |
| CVE-2026-96897 | Optima Express 8.5.0 - 8.7.5 - Unauthenticated Author Account Creation & Application Passw | |
| CVE-2026-96895 | WP YouTube Lyte < 1.7.31 - Contributor+ Stored XSS via Embed Block Attributes | |
| CVE-2026-92995 | Verge3D <= 4.13.0 - Unauthenticated Product Download Disclosure via v3d_download_file | |
| CVE-2026-92436 | Mailchimp for WooCommerce < 6.3 - Unauthenticated Customer Email and Cart Disclosure via I | |
| CVE-2026-97319 | PowerPress < 11.17.2 - Contributor+ Stored XSS via Podcast Player Block | |
| CVE-2026-97227 | NextScripts: Social Networks Auto-Poster < 4.4.8 - Authenticated Social Account Credential |
No comments yet