PT-2025-49801 · WordPress · Wpematico Rss Feed Fetcher

·

CVE-2025-13031

·

Published

2025-12-09

·

Updated

2025-12-09

CVSS v3.1

5.9

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WPeMatico RSS Feed Fetcher WordPress plugin versions prior to 2.8.13
Description The WPeMatico RSS Feed Fetcher WordPress plugin does not properly sanitize and escape certain settings. This could allow users with high privileges, such as contributors, to carry out Stored Cross-Site Scripting (XSS) attacks. Stored XSS occurs when malicious scripts are persistently stored on the target server, and then delivered to other users.
Recommendations Update to version 2.8.13 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2025-13031

Affected Products

Wpematico Rss Feed Fetcher