8.8

CVE-2026-19883

WPeMatico RSS Feed Fetcher <= 2.8.24 - Authenticated (Subscriber+) Privilege Escalation via Arbitrary Option Update to wpematico_import_settings admin_action

WPeMatico RSS Feed Fetcher <= 2.8.24 - Authenticated (Subscriber+) Privilege Escalation via Arbitrary Option Update to wpematico_import_settings admin_action

The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the wpematico_import_settings function in all versions up to, and including, 2.8.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access.
Mögliche Gegenmaßnahme
WPeMatico RSS Feed Fetcher: Update to version 2.8.25, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstelleretruel
≫
Produkt WPeMatico RSS Feed Fetcher
Default Statusunaffected
Version <= 2.8.24
Version 0
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt WPeMatico RSS Feed Fetcher
Version *-2.8.24
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.301
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@wordfence.com 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

https://github.com/etruel/wpematico/commit/e297f41b49c6ec76635b006dff8a964a99a1ed24
https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.23/app/tools_page.php#L224
https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.23/app/wpematico_functions.php#L2077
https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.23/app/wpematico_functions.php#L2096
https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.23/wpematico_class.php#L59
https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.24/app/tools_page.php#L224
https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.24/app/wpematico_functions.php#L2077
https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.24/app/wpematico_functions.php#L2096
https://plugins.trac.wordpress.org/browser/wpematico/tags/2.8.24/wpematico_class.php#L59
https://www.wordfence.com/threat-intel/vulnerabilities/id/4e591cb4-058d-4d8e-948e-d65ab01db618?source=cve
https://www.wordfence.com/threat-intel/vulnerabilities/id/4e591cb4-058d-4d8e-948e-d65ab01db618
Third Party Advisory