Junglewise Threat Intelligence

CVE-2026-57349: etruel WPeMatico RSS Feed Fetcher unauthenticated XSS

CVE-2026-57349 · Severity: high · CVSS 7.1 · Published 2026-07-02

Executive brief

WPeMatico RSS Feed Fetcher, a WordPress plugin used to automatically import content from RSS feeds, contains a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, the attacker's script can execute in their browser. This could lead to unauthorized actions, such as redirecting users to malicious sites, displaying fraudulent advertisements, or potentially hijacking administrative sessions.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the WPeMatico RSS Feed Fetcher plugin for WordPress due to improper neutralization of input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject malicious HTML or JavaScript payloads. Exploitation requires a victim (typically a privileged user) to perform an action, such as clicking a malicious link or visiting a crafted page. Successful exploitation results in the execution of the script in the context of the victim's browser session, which can lead to session theft or site defacement. The issue is addressed in version 2.8.18.

Affected products

  • etruel WPeMatico RSS Feed Fetcher <= 2.8.17

Timeline

  • 2026-05-23: disclosed: Reported by João Pedro S Alcântara (Kinorth)
  • 2026-07-01: advisory: Patchstack advisory published
  • 2026-07-02: patched: NVD publication and confirmation of version 2.8.18 as the fix

References