Unauthorized Data Modification in WPeMatico RSS Feed Fetcher Plugin by WordPress
CVE-2026-19883

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 August 2026

What is CVE-2026-19883?

The WPeMatico RSS Feed Fetcher plugin for WordPress is flawed due to a missing capability check on the function responsible for importing settings. This vulnerability permits authenticated users with at least subscriber-level access to alter site settings. Consequently, attackers can exploit this issue to alter the default registration role, enabling unauthorized user registration and potentially gaining administrative access to the site.

Affected Version(s)

WPeMatico RSS Feed Fetcher 0 <= 2.8.24

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Supakiad S. (m3ez)
.