Sceawere
Vulnerability Detail
CVE-2026-89006UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WPeMatico Stored XSS Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 1d ago
- Vendor
- Unknown
- Product
- WPeMatico RSS Feed Fetcher
- Attack Type
- CWE-79 Cross-Site Scripting (XSS)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-09-27T06:17:22.377Z",
"pubdate": "2026-09-27T06:17:22.377Z",
"executiveSummary": "The WPeMatico RSS Feed Fetcher plugin for WordPress, in versions prior to 2.8.27, contains a critical Stored Cross-Site Scripting (XSS) vulnerability.\nThis flaw arises from the improper sanitization of ingested RSS feed content before it is persisted into the WordPress database as post content.\nAn authenticated user with a role of Contributor or higher can leverage this vulnerability to inject malicious scripts into the application.\nWhen a victim, such as an administrator or other high-privileged user, views the rendered content, the injected script executes within the context of their session.\nThe impact includes potential session hijacking, unauthorized actions performed on behalf of the victim, and the compromise of sensitive data.\nThis vulnerability highlights a failure in input validation protocols during the content ingestion phase of the plugin's operation, necessitating immediate remediation to maintain site integrity.",
"technicalDetails": "The root cause of this vulnerability is the absence of adequate input sanitization and output escaping mechanisms within the WPeMatico plugin when processing incoming RSS feed data. Specifically, the plugin fails to strip or neutralize executable HTML or JavaScript payloads contained within RSS elements (e.g., <item> descriptions or content tags) before these elements are processed and stored as WordPress post content.\nThe attack vector requires the adversary to have an authenticated account with at least Contributor-level privileges, which is the minimum permission level required to configure or interact with the feed fetching functionality of the plugin.\nThe exploitation flow begins with the attacker creating or modifying an RSS feed source within the WPeMatico plugin interface. The attacker points the feed to a malicious RSS source controlled by the attacker. This source contains crafted payload elements, such as <script> tags or malicious event handlers embedded within the XML structure.\nUpon triggering the feed fetch process, the plugin retrieves the malicious content from the remote source. Because the plugin performs no validation, the raw malicious payload is directly injected into the database-backed 'post_content' field for the newly created or updated post.\nThe vulnerability is realized when the malicious post is accessed or viewed by another user within the WordPress dashboard or the public-facing site. The browser interprets the injected payload as legitimate content and executes the script within the user's active session context.\nBecause the execution occurs in the context of the victim's session, an attacker can bypass standard security controls, potentially leading to unauthorized API calls, credential harvesting, or further compromise of the WordPress environment. The lack of output encoding ensures that the malicious payload is rendered unfiltered, facilitating the persistent nature of the XSS attack.\nAffected versions are strictly limited to those prior to 2.8.27. As the plugin directly writes ingested data to the content body without sanitization, it violates secure coding practices for handling untrusted third-party input."
}