VYPR

Wpematico

by Etruel

Source repositories

CVEs (3)

  • CVE-2026-19883HigAug 22, 2026
    risk 0.50cvss 8.8epss

    The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the wpematico_import_settings function in all versions up to, and including, 2.8.24. This makes it…

  • CVE-2025-11917MedNov 5, 2025
    risk 0.35cvss 6.4epss 0.00

    The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.11 via the wpematico_test_feed() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…

  • CVE-2025-8103MedJul 26, 2025
    risk 0.21cvss 4.3epss 0.00

    The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.7. This is due to missing nonce validation in the handle_feedback_submission() function. This makes it possible for unauthenticated attackers…