The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
PUBLISHED5.2
WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Stored XSS via Feed Import
Problem type
- CWE-79 Cross-Site Scripting (XSS)
Affected products
Unknown
WPeMatico RSS Feed Fetcher
< 2.8.27 - AFFECTED
References
GitHub Security Advisories
GHSA-f35c-fj5h-9hj5
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed...
https://github.com/advisories/GHSA-f35c-fj5h-9hj5The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-89006Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-89006",
"assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"assignerShortName": "WPScan",
"dateUpdated": "2026-09-27T06:00:21.446Z",
"dateReserved": "2026-09-10T16:19:39.229Z",
"datePublished": "2026-09-27T06:00:21.446Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81",
"shortName": "WPScan",
"dateUpdated": "2026-09-27T06:00:21.446Z"
},
"title": "WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Stored XSS via Feed Import",
"descriptions": [
{
"lang": "en",
"value": "The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks."
}
],
"affected": [
{
"vendor": "Unknown",
"product": "WPeMatico RSS Feed Fetcher",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "semver",
"lessThan": "2.8.27"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-79 Cross-Site Scripting (XSS)",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://wpscan.com/vulnerability/680091de-610a-4665-a028-515ca6c33055/",
"tags": [
"exploit",
"vdb-entry",
"technical-description"
]
}
],
"credits": [
{
"lang": "en",
"value": "Philipp Doblhofer",
"type": "finder"
},
{
"lang": "en",
"value": "WPScan",
"type": "coordinator"
}
]
}
}
}