Sceawere
Vulnerability Detail
CVE-2026-89001UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WPeMatico Improper Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.9
- Creation Date
- 1d ago
- Vendor
- Unknown
- Product
- WPeMatico RSS Feed Fetcher
- Attack Type
- CWE-269 Improper Privilege Management
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is permitted to publish content or to attribute posts to another account, allowing users with contributor-level access and above to publish posts live and set any registered user, including an administrator, as the post author.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.9",
"pubDate": "2026-09-27T06:17:19.397Z",
"pubdate": "2026-09-27T06:17:19.397Z",
"executiveSummary": "The WPeMatico RSS Feed Fetcher WordPress plugin before version 2.8.27 contains an authorization bypass vulnerability related to feed campaign management.\nThe vulnerability allows users with contributor-level privileges or higher to execute unauthorized actions, specifically the live publishing of content and the arbitrary assignment of post authorship.\nBy manipulating feed campaign parameters, an attacker can bypass standard WordPress permission controls that restrict non-administrative users from publishing directly to the live site or impersonating other registered users, including administrators.\nThis flaw compromises the integrity of the WordPress installation by enabling unauthorized content injection and identity spoofing. The risk is significant as it elevates the capability of lower-privileged users to perform actions reserved for editors or administrators, potentially leading to unauthorized data dissemination, reputation damage, or further escalation of privilege through social engineering via authored posts.\nExploitation requires active authentication with at least contributor-level access to the WordPress dashboard.",
"technicalDetails": "The root cause of this vulnerability lies in an insufficient implementation of access control checks within the plugin's feed campaign processing logic. Specifically, the plugin fails to validate whether the authenticated user interacting with the feed campaign interface possesses the appropriate 'edit_posts' or 'publish_posts' capabilities required to perform sensitive operations.\nThe vulnerability is triggered during the execution of feed campaigns where the plugin permits the definition of post attributes. The application logic lacks a server-side verification layer to ensure that the user initiating or editing the campaign is authorized to manipulate post status or override the 'post_author' field.\nThe attack flow proceeds as follows: First, an authenticated attacker with contributor-level access navigates to the WPeMatico campaign configuration panel. Second, the attacker creates or modifies a feed campaign. Because the plugin does not verify user roles against the intended action, the attacker can set the post status to 'publish' rather than the default 'pending' state typical for contributors. Third, the attacker leverages the improperly secured interface to assign the 'post_author' attribute to any existing user ID on the system, including administrative accounts.\nWhen the RSS fetcher processes the feed items, the plugin generates posts using the attacker-controlled parameters. The WordPress database then reflects these posts as live content published by the selected (and often unauthorized) account. This bypasses the standard WordPress content moderation workflow where contributors are typically restricted to creating 'pending' posts that must be approved by an editor or administrator.\nThe lack of integrity checks in the plugin's data processing routines ensures that the post creation function proceeds without confirming the authorization of the requestor. This allows for the mass publication of malicious or unauthorized content that appears to originate from trusted, high-privileged users. The impact is significant, as it effectively grants any contributor the ability to publish content at will and impersonate other system users, undermining the security model of the WordPress site."
}