Sceawere
Vulnerability Detail
CVE-2026-89003UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WPeMatico SSRF Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.1
- Creation Date
- 1d ago
- Vendor
- Unknown
- Product
- WPeMatico RSS Feed Fetcher
- Attack Type
- CWE-918 Server-Side Request Forgery (SSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user-supplied URL and rendering the response, allowing users with contributor-level access and above to force the server to issue requests to internal-only hosts and read the responses back.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.1",
"pubDate": "2026-09-27T06:17:22.270Z",
"pubdate": "2026-09-27T06:17:22.270Z",
"executiveSummary": "The WPeMatico RSS Feed Fetcher plugin for WordPress, specifically in versions prior to 2.8.27, is susceptible to a Server-Side Request Forgery (SSRF) vulnerability. This flaw arises from the application's failure to perform adequate authorization checks or validate user-supplied URLs before initiating backend HTTP requests. By exploiting this vulnerability, authenticated attackers with contributor-level privileges or higher can force the underlying web server to execute arbitrary outbound HTTP requests to internal network resources. This circumvents perimeter security controls, enabling the attacker to interact with services residing within the internal network that are typically inaccessible from the public internet. The primary risk involves unauthorized data exfiltration, service enumeration, and potential interaction with internal APIs or metadata services (such as those in cloud environments like AWS EC2). Successful exploitation requires active authentication, but the low privilege requirement significantly expands the attack surface for multi-user WordPress installations.",
"technicalDetails": "The vulnerability resides in the request processing logic of the WPeMatico RSS Feed Fetcher plugin, which handles the fetching and parsing of external RSS feed resources. The root cause is an improper authorization check combined with insufficient input sanitization regarding target URL parameters. Specifically, the plugin functions responsible for fetching remote content fail to verify if the requesting user possesses the necessary administrative capabilities before executing network requests.\nThe attack flow begins when a malicious user with at least Contributor-level access sends a crafted request to the WPeMatico component. By manipulating specific URL parameters, an attacker can designate the target of the HTTP request to be an internal IP address (e.g., 127.0.0.1, 192.168.x.x) or sensitive local services like the loopback interface, internal databases, or cloud provider metadata endpoints (e.g., 169.254.169.254). The plugin proceeds to fetch the content from the attacker-defined URL and reflects the response back to the user interface, effectively turning the server into an open proxy.\nBecause the server initiates these requests, they originate from a trusted internal source. This allows the attacker to bypass firewall restrictions and access non-public endpoints. The impact is significant: an attacker can enumerate internal network topology, identify running services based on port scanning and banner grabbing, and potentially interact with internal REST APIs that lack secondary authentication. Furthermore, in cloud-hosted environments, this vulnerability could be leveraged to retrieve sensitive instance metadata or security credentials associated with the IAM role assigned to the web server instance. The flaw remains persistent until the update to version 2.8.27 is applied, which introduces appropriate permission checks and potentially stricter URL validation logic to constrain the plugin's interaction scope."
}