CVE-2026-89000 PUBLISHED

WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Run

Assigner: WPScan
Reserved: 10.09.2026 Published: 27.09.2026 Updated: 27.09.2026

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destination of a user-supplied feed URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to internal-only resources and read the responses back.

Product Status

Vendor Unknown
Product WPeMatico RSS Feed Fetcher
Versions Default: unaffected
  • affected from 0 to 2.8.27 (excl.)

Credits

  • JunHee CHO finder
  • WPScan coordinator

References

Problem Types

  • CWE-918 Server-Side Request Forgery (SSRF) CWE