Cross-Site Request Forgery Vulnerability in WPeMatico RSS Feed Fetcher Plugin for WordPress
CVE-2025-8103
4.3MEDIUM
What is CVE-2025-8103?
The WPeMatico RSS Feed Fetcher plugin for WordPress is susceptible to Cross-Site Request Forgery due to insufficient nonce validation in the handle_feedback_submission() function. This vulnerability enables unauthorized attackers to deactivate the plugin by tricking an administrator into executing a crafted request, potentially leading to control over the site's RSS functionalities.
Affected Version(s)
WPeMatico RSS Feed Fetcher * <= 2.8.7