PatchSiren

WPeMatico CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM WPeMatico CVE published 2026-09-27

CVE-2026-89006

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks. This vulnerability can lead to potential Stored Cross-Site Scripting attacks against users with Contributor role and above. Defenders should assess exposure and prioritize [truncated]

MEDIUM WPeMatico CVE published 2026-09-27

CVE-2026-89003

CVE-2026-89003 is a vulnerability in the WPeMatico RSS Feed Fetcher WordPress plugin that allows users with contributor-level access and above to force the server to issue requests to internal-only hosts and read the responses back. This could potentially lead to unauthorized access and data exposure. Defenders should assess exposure and verify that users with contributor-level access and above do not hav [truncated]

MEDIUM WPeMatico CVE published 2026-09-27

CVE-2026-89001

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is permitted to publish content or to attribute posts to another account, allowing users with contributor-level access and above to publish posts live and set any registered user, including an administrator, as the post author. This vulnerability could lead to unauthorized post publication and [truncated]

MEDIUM WPeMatico CVE published 2026-09-27

CVE-2026-89000

CVE-2026-89000 is a medium-severity vulnerability in the WPeMatico RSS Feed Fetcher WordPress plugin. It allows users with contributor-level access and above to make unauthorized requests to internal resources and read responses. This issue arises because the plugin does not perform a capability check or validate the destination of a user-supplied feed URL before fetching it server-side. WordPress site ad [truncated]