WordPress · Wpematico Rss Feed Fetcher · CVE-2026-89005
**Name of the Vulnerable Software and Affected Versions**
WPeMatico RSS Feed Fetcher versions prior to 2.8.26
**Description**
The plugin fails to sanitize and escape a campaign configuration field when a specific feature is enabled. This allows users with the Contributor role or higher to perform Stored Cross-Site Scripting (XSS) attacks. These attacks execute within the session of any higher-privileged user who views the affected campaign.
**Recommendations**
Update WPeMatico RSS Feed Fetcher to version 2.8.26 or later.