PT-2026-79502 · WordPress · Wpematico Rss Feed Fetcher
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WPeMatico RSS Feed Fetcher versions prior to 2.8.25
Description
The plugin is susceptible to unauthorized data modification leading to privilege escalation. This occurs because the
wpematico import settings() function lacks a proper capability check. Authenticated users with subscriber-level access or higher can exploit this to update arbitrary options on the WordPress site, such as changing the default registration role to administrator and enabling user registration to gain full administrative access.Recommendations
Update WPeMatico RSS Feed Fetcher to version 2.8.25 or later.
As a temporary mitigation, restrict access to the
wpematico import settings() function for users with low-level privileges.Exploit
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpematico Rss Feed Fetcher