WordPress Plugin Vulnerabilities

WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Campaign Configuration and Log Disclosure via IDOR

Description

The plugin does not verify ownership or authorization before returning a campaign's stored configuration and run log, allowing users with contributor-level access and above to read the configuration and execution logs of campaigns created by other users, including administrators.

Proof of Concept

Affects Plugins

Fixed in 2.8.26

References

Classification

Type
IDOR
CWE
CVSS

Miscellaneous

Original Researcher
Karthik Ramakrishnan
Submitter
Karthik Ramakrishnan
Verified
Yes

Timeline

Publicly Published
2026-09-22 (about 2 days ago)
Added
2026-09-22 (about 1 day ago)
Last Updated
2026-09-22 (about 1 day ago)

Other