Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

WPeMatico RSS Feed Fetcher — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in WPeMatico RSS Feed Fetcher, with AI-generated Chinese analysis, references, and POCs.

This page documents known security vulnerabilities associated with WPeMatico RSS Feed Fetcher, focusing on common weakness classifications and specific product tags. It aggregates a comprehensive collection of security issues, ranging from critical remote code execution flaws to less severe information disclosure and cross-site scripting vulnerabilities, covering reported incidents from early 2020 through late 2023. Users can utilize this resource to track vendor advisories and monitor how WPeMatico addresses security concerns over time. The detailed entries allow developers and security analysts to understand the specific weakness classes affecting this WordPress plugin, providing context on the nature of each flaw and its potential impact on site integrity. Additionally, the page serves as a historical reference for looking up a product's vulnerability history, enabling teams to assess past risks and evaluate the current security posture of their installations. By centralizing this data, the page facilitates easier identification of patterns in software defects and supports informed decision-making regarding updates, patches, and migration strategies. This structured approach helps organizations mitigate risks by providing clear, actionable insights into the security landscape surrounding WPeMatico RSS Feed Fetcher without requiring manual searches across multiple disparate sources.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-89000 WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Run - - 2026-09-27
CVE-2026-89006 WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Stored XSS via Feed Import - - 2026-09-27
CVE-2026-89003 WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Preview - - 2026-09-27
CVE-2026-89001 WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Post Publication and Author Spoofing via Campaign Settings - - 2026-09-27
CVE-2026-89004 WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Campaign Configuration and Log Disclosure via IDOR - - 2026-09-24
CVE-2026-89005 WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Word to Category - - 2026-09-24
CVE-2026-89002 WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Campaign Item Preview - - 2026-09-24
CVE-2026-19883 WPeMatico RSS Feed Fetcher <= 2.8.24 - Authenticated (Subscriber+) Privilege Escalation via Arbitrary Option Update to wpematico_import_settings admin_action CWE-269 8.8 High 2026-08-22
CVE-2026-57349 WordPress WPeMatico RSS Feed Fetcher plugin <= 2.8.17 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2026-07-02
CVE-2025-13031 WPeMatico RSS Feed Fetcher < 2.8.13 - Contributor+ Stored XSS 4.8AI Medium AI 2025-12-09
CVE-2025-11917 WPeMatico RSS Feed Fetcher <= 2.8.11 - Authenticated (Subscriber+) Server-Side Request Forgery via wpematico_test_feed CWE-918 6.4 Medium 2025-11-05
CVE-2025-49922 WordPress WPeMatico RSS Feed Fetcher plugin <= 2.8.3 - Broken Access Control vulnerability CWE-862 4.3 Medium 2025-10-22
CVE-2025-57937 WordPress WPeMatico RSS Feed Fetcher Plugin <= 2.8.10 - Sensitive Data Exposure Vulnerability CWE-497 4.3 Medium 2025-09-22
CVE-2025-8103 WPeMatico RSS Feed Fetcher <= 2.8.7 - Cross-Site Request Forgery to Plugin Deactivation via handle_feedback_submission Function CWE-352 4.3 Medium 2025-07-26
CVE-2021-24793 WPeMatico RSS Feed Fetcher < 2.6.12 - Admin+ Stored Cross-Site Scripting CWE-79 4.8 - 2021-11-01

All 15 known CVE vulnerabilities affecting WPeMatico RSS Feed Fetcher with full Chinese analysis, references, and POCs where available.