CVE-2026-89004: WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Campaign Configuration and Log Disclosure via IDOR
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returning a campaign's stored configuration and run log, allowing users with contributor-level access and above to read the configuration and execution logs of campaigns created by other users, including administrators.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WPeMatico RSS Feed Fetcherto a version that resolves this vulnerability.Fixed in 2.8.26
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user with contributor-level access or higher can access campaign configuration and run logs belonging to campaigns created by other users, including administrators.
What information could be exposed?
The issue exposes stored campaign configuration and campaign execution logs. The provided information does not specify which individual configuration values or log entries may be present.
Are installations running version 2.8.26 affected?
The issue affects WPeMatico RSS Feed Fetcher versions before 2.8.26. The provided information does not identify any affected versions at or after 2.8.26.