CVE WATCH / VULNERABILITY DETAIL

CVE-2026-89003

UNKNOWNCVSS 0NVD feed

Published 27 September 2026 · tracked since 27 September 2026

Description

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user-supplied URL and rendering the response, allowing users with contributor-level access and above to force the server to issue requests to internal-only hosts and read the responses

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-89003 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-89003

UNKNOWNCVSS 0NVD feed

Published 27 September 2026 · tracked since 27 September 2026

Description

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check before fetching a user-supplied URL and rendering the response, allowing users with contributor-level access and above to force the server to issue requests to internal-only hosts and read the responses

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]