WPeMatico RSS Feed Fetcher WordPress 插件在 2.8.27 版本之前,在获取用户提供的 URL 并渲染响应内容之前,未进行权限检查。该漏洞允许拥有“贡献者”(contributor)及以上级别权限的用户,强制服务器向仅内部可访问的主机发起请求,并将响应内容读回。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WPeMatico RSS Feed Fetcher | 0 ~ 2.8.27 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89006 | WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Stored XSS via Feed Import | |
| CVE-2026-84069 | WebFacing Email Accounts for cPanel 5.3 - 5.3.6 - Unauthenticated LFI via assets/index.php | |
| CVE-2026-81655 | Ad Inserter 2.8.12 - 2.8.18 - Subscriber+ RCE / Stored XSS via Global Custom Fields | |
| CVE-2026-82841 | UpdraftPlus 1.23.8 - 1.26.7 - Subscriber+ Remote Storage Credential Disclosure via Migrati | |
| CVE-2026-85002 | EmbedPress < 4.6.7 - Contributor+ Stored XSS via Instagram Carousel Block Attributes | |
| CVE-2026-86609 | Download Manager Pro < 7.5.6 - Unauthenticated Stored XSS via Email Lock Subscription | |
| CVE-2026-86839 | Bookly < 28.3 - Staff+ Appointment and Payment Disclosure, Modification and Deletion via I | |
| CVE-2026-86841 | Bookly 23.2 - 28.2 - Bookly Administrator+ PHP Object Injection via Diagnostics Advanced O | |
| CVE-2026-89001 | WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Post Publication and Author Spoofing vi | |
| CVE-2026-96899 | Optima Express 8.6.0 - 8.7.5 - Author+ Stored XSS via faq_script | |
| CVE-2026-89000 | WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Run | |
| CVE-2026-96896 | Malcure Malware Shield < 19.9.7 - Multisite Subsite Admin+ Arbitrary File Write and Deleti | |
| CVE-2026-96897 | Optima Express 8.5.0 - 8.7.5 - Unauthenticated Author Account Creation & Application Passw | |
| CVE-2026-96895 | WP YouTube Lyte < 1.7.31 - Contributor+ Stored XSS via Embed Block Attributes | |
| CVE-2026-92995 | Verge3D <= 4.13.0 - Unauthenticated Product Download Disclosure via v3d_download_file | |
| CVE-2026-92436 | Mailchimp for WooCommerce < 6.3 - Unauthenticated Customer Email and Cart Disclosure via I | |
| CVE-2026-97319 | PowerPress < 11.17.2 - Contributor+ Stored XSS via Podcast Player Block | |
| CVE-2026-97227 | NextScripts: Social Networks Auto-Poster < 4.4.8 - Authenticated Social Account Credential |
No comments yet