PT-2025-49801 · WordPress · Wpematico Rss Feed Fetcher

Alex Tselevich

·

Published

2025-12-09

·

Updated

2025-12-09

·

CVE-2025-13031

CVSS v3.1

5.9

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WPeMatico RSS Feed Fetcher WordPress plugin versions prior to 2.8.13
Description The WPeMatico RSS Feed Fetcher WordPress plugin does not properly sanitize and escape certain settings. This could allow users with high privileges, such as contributors, to carry out Stored Cross-Site Scripting (XSS) attacks. Stored XSS occurs when malicious scripts are persistently stored on the target server, and then delivered to other users.
Recommendations Update to version 2.8.13 or later.

Exploit

Fix

Related Identifiers

CVE-2025-13031

Affected Products

Wpematico Rss Feed Fetcher