cleantalk
Vulnerabilities and Security Researches

WPeMatico RSS Feed Fetcher, CVE-2026-89006

CVE, Research URL

CVE-2026-89006

Published on
Sep 27, 2026
Research Description
The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected versions
max 2.8.27.
Status
vulnerable