Executive brief
WPeMatico is a popular WordPress plugin that automatically imports and publishes content from RSS feeds. Due to missing authorization checks in its settings import function, any authenticated user with subscriber-level access or higher can modify critical WordPress settings without proper permission. An attacker can exploit this to change the default user registration role to administrator and enable user registration, allowing them to create an admin account and take over the WordPress site.
Technical details
This vulnerability is a privilege escalation resulting from a missing capability check in the wpematico_import_settings function. The affected function allows modification of arbitrary WordPress options without verifying whether the authenticated user has the required administrative permissions. An authenticated attacker with subscriber-level access or above can invoke this function to modify options such as default_role and users_can_register, effectively bypassing access controls. By setting the default registration role to administrator and enabling user registration, the attacker can create new administrator accounts and gain full site access. The vulnerability was patched in version 2.8.25 (released August 15, 2026) by adding proper capability checks and input validation.
Affected products
- Evonik WPeMatico RSS Feed Fetcher up to and including 2.8.24
Timeline
- 2026-08-22: disclosed
- 2026-08-15: patched: Version 2.8.25 released with capability checks added