8.8
CVE-2026-19883
- EPSS 0.37%
- Veröffentlicht 22.08.2026 03:16:20
- Zuletzt bearbeitet 24.08.2026 16:41:13
- Erkennungen
WPeMatico RSS Feed Fetcher <= 2.8.24 - Authenticated (Subscriber+) Privilege Escalation via Arbitrary Option Update to wpematico_import_settings admin_action
WPeMatico RSS Feed Fetcher <= 2.8.24 - Authenticated (Subscriber+) Privilege Escalation via Arbitrary Option Update to wpematico_import_settings admin_action
The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the wpematico_import_settings function in all versions up to, and including, 2.8.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access.
Mögliche Gegenmaßnahme
WPeMatico RSS Feed Fetcher: Update to version 2.8.25, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstelleretruel
≫
Produkt
WPeMatico RSS Feed Fetcher
Default Statusunaffected
Version <=
2.8.24
Version
0
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
WPeMatico RSS Feed Fetcher
Version
*-2.8.24
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.37% | 0.301 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
https://github.com/etruel/wpematico/commit/e297f41b49c6ec76635b006dff8a964a99a1ed24
https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.23/app/tools_page.php#L224
https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.23/app/wpematico_functions.php#L2077
https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.23/app/wpematico_functions.php#L2096
https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.23/wpematico_class.php#L59
https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.24/app/tools_page.php#L224
https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.24/app/wpematico_functions.php#L2077
https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.24/app/wpematico_functions.php#L2096
https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.24/wpematico_class.php#L59
https://www.wordfence.com/threat-intel/vulnerabilities/id/4e591cb4-058d-4d8e-948e-d65ab01db618?source=cve
https://www.wordfence.com/threat-intel/vulnerabilities/id/4e591cb4-058d-4d8e-948e-d65ab01db618