Etruel

Wpematico Rss Feed Fetcher

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 05.11.2025 06:34:59
  • Zuletzt bearbeitet 06.11.2025 19:45:30

The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.11 via the wpematico_test_feed() function. This makes it possible for authenticated attackers, with Subscriber-...

  • EPSS 0.07%
  • Veröffentlicht 22.10.2025 14:32:13
  • Zuletzt bearbeitet 20.01.2026 15:16:41

Missing Authorization vulnerability in etruel WPeMatico RSS Feed Fetcher wpematico allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPeMatico RSS Feed Fetcher: from n/a through <= 2.8.3.

  • EPSS 0.04%
  • Veröffentlicht 22.09.2025 18:25:01
  • Zuletzt bearbeitet 22.09.2025 21:22:33

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in etruel WPeMatico RSS Feed Fetcher allows Retrieve Embedded Sensitive Data. This issue affects WPeMatico RSS Feed Fetcher: from n/a through 2.8.10.

  • EPSS 0.02%
  • Veröffentlicht 26.07.2025 03:38:18
  • Zuletzt bearbeitet 29.07.2025 14:14:55

The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.7. This is due to missing nonce validation in the handle_feedback_submission() function. This makes it possible ...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 01.11.2021 09:15:09
  • Zuletzt bearbeitet 21.11.2024 05:53:46

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.6.12 does not escape the Feed URL added to a campaign before outputting it in an attribute, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html c...