2026-09-27 6:0CVE-2026-89006WPScan
PUBLISHED5.2

WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Stored XSS via Feed Import

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.

Problem type

  • CWE-79 Cross-Site Scripting (XSS)

Affected products

Unknown

WPeMatico RSS Feed Fetcher

< 2.8.27 - AFFECTED

References

GitHub Security Advisories

GHSA-f35c-fj5h-9hj5

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed...

https://github.com/advisories/GHSA-f35c-fj5h-9hj5

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-89006
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-89006",
    "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
    "assignerShortName": "WPScan",
    "dateUpdated": "2026-09-27T06:00:21.446Z",
    "dateReserved": "2026-09-10T16:19:39.229Z",
    "datePublished": "2026-09-27T06:00:21.446Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
        "shortName": "WPScan",
        "dateUpdated": "2026-09-27T06:00:21.446Z"
      },
      "title": "WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Stored XSS via Feed Import",
      "descriptions": [
        {
          "lang": "en",
          "value": "The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks."
        }
      ],
      "affected": [
        {
          "vendor": "Unknown",
          "product": "WPeMatico RSS Feed Fetcher",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "semver",
              "lessThan": "2.8.27"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-79 Cross-Site Scripting (XSS)",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://wpscan.com/vulnerability/680091de-610a-4665-a028-515ca6c33055/",
          "tags": [
            "exploit",
            "vdb-entry",
            "technical-description"
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Philipp Doblhofer",
          "type": "finder"
        },
        {
          "lang": "en",
          "value": "WPScan",
          "type": "coordinator"
        }
      ]
    }
  }
}