CVE 5.4 MEDIUM

WPeMatico RSS Feed Fetcher < 2.8.13 - Contributor+ Stored XSS_CVE-2025-13031

5.4 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Description

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.13 does not sanitize and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

Basic Information

ID CVE-2025-13031
Source WPScan
Published Dec 9, 2025 at 06:00
Modified Dec 11, 2025 at 14:36

Affected Product

Vendor Unknown
Product WPeMatico RSS Feed Fetcher
Affected Versions Unknown WPeMatico RSS Feed Fetcher 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.