CVE-2026-89003: WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Preview
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user-supplied URL and rendering the response, allowing users with contributor-level access and above to force the server to issue requests to internal-only hosts and read the responses back.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user with contributor-level access or higher can exploit it. The affected plugin does not enforce a capability check before performing the campaign preview fetch.
What access does an attacker need to use the SSRF?
The attacker needs an account on the WordPress site with at least the Contributor role and must be able to supply a URL through the campaign preview functionality. Exploitation does not require the target internal host to be directly reachable by the attacker.
What can an attacker obtain through a successful request?
An attacker can cause the WordPress server to send requests to internal-only hosts and can read the returned responses. This may expose services or data reachable from the server but not from the public internet.
Which versions are affected?
WPeMatico RSS Feed Fetcher versions before 2.8.27 are affected. Version 2.8.27 is the stated fixed-version boundary.