Stored Cross-Site Scripting Vulnerability in WPeMatico RSS Feed Fetcher Plugin
CVE-2026-89002
Currently unrated
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 September 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-89002?
The WPeMatico RSS Feed Fetcher plugin for WordPress prior to version 2.8.26 fails to adequately sanitize and escape content retrieved from user-supplied sources. This oversight can enable contributors to exploit the vulnerability and execute Stored Cross-Site Scripting attacks, affecting higher-privileged users who review the campaigns. As a result, it poses a significant risk of injecting malicious scripts, allowing the attacker to manipulate web sessions or phish sensitive information.
Affected Version(s)
WPeMatico RSS Feed Fetcher 0 < 2.8.26
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.