CVE-2026-89005: WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Word to Category
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configuration fields when a certain feature is enabled, which allows users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the session of any higher-privileged user who later views the campaign.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WPeMatico RSS Feed Fetcherto a version that resolves this vulnerability.Fixed in 2.8.26
Event History
Frequently Asked Questions
Who can exploit this issue?
A user with the Contributor role or any higher-privileged role can exploit it. Exploitation requires access to configure a campaign.
When does the stored script execute?
The script executes when a higher-privileged user later views the affected campaign. The vulnerable configuration field is only implicated when the relevant feature is enabled.
Which installations are affected?
WPeMatico RSS Feed Fetcher versions before 2.8.26 are affected. The issue depends on the relevant campaign feature being enabled.