CVE-2026-89000

CVE-2026-89000 published: The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destination of a user-supplied feed URL before fetching it server-side, allowing users with contributor-level access and above to make the serv...

View full NVD advisory → ← Back to CVE watch