WordPress Plugin Vulnerabilities

WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Word to Category

Description

The plugin does not sanitise and escape one of its campaign configuration fields when a certain feature is enabled, which allows users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the session of any higher-privileged user who later views the campaign.

Proof of Concept

Affects Plugins

Fixed in 2.8.26

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
achmad sonif
Submitter
achmad sonif
Verified
Yes

Timeline

Publicly Published
2026-09-22 (about 2 days ago)
Added
2026-09-22 (about 1 day ago)
Last Updated
2026-09-22 (about 1 day ago)

Other