{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wpematico-rss-feed-fetcher-2.8.24/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-19883"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WPeMatico RSS Feed Fetcher (2.8.24)"],"_cs_severities":["high"],"_cs_tags":["wordpress","privilege-escalation","vulnerability"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe WPeMatico RSS Feed Fetcher plugin for WordPress (versions 2.8.24 and earlier) contains a critical security flaw involving the wpematico_import_settings function. The plugin fails to perform adequate capability checks when processing settings imports, allowing authenticated attackers with subscriber-level access to modify arbitrary options within the WordPress database.\u003c/p\u003e\n\u003cp\u003eBy manipulating these options, an attacker can change the default user registration role to 'administrator' and enable the site's user registration feature. This allows the attacker to create new administrative accounts or elevate existing low-privileged accounts, granting them full control over the WordPress installation. This vulnerability represents a significant risk for site integrity and requires immediate patching of the plugin to the version containing the fix.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows an authenticated attacker to achieve full administrative control over a WordPress site. By altering default site options such as 'users_can_register' and 'default_role', an attacker can bypass standard registration controls to gain elevated access. This impact extends to any organization utilizing the WPeMatico plugin, potentially affecting the confidentiality, integrity, and availability of the entire WordPress platform.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the WPeMatico RSS Feed Fetcher plugin to the latest patched version immediately.\u003c/li\u003e\n\u003cli\u003eAudit WordPress site options for unauthorized changes to the 'default_role' or 'users_can_register' settings.\u003c/li\u003e\n\u003cli\u003eImplement stricter access control monitoring for plugins that perform sensitive database updates.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-22T03:27:54Z","date_published":"2026-08-22T03:27:54Z","id":"https://feed.craftedsignal.io/briefs/2026-08-wpematico-priv-esc/","summary":"An unauthenticated or low-privilege authenticated user can leverage a missing capability check in the wpematico_import_settings function to modify site options, enabling unauthorized privilege escalation.","title":"Privilege Escalation in WPeMatico RSS Feed Fetcher Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-08-wpematico-priv-esc/"}],"language":"en","title":"CraftedSignal Threat Feed - WPeMatico RSS Feed Fetcher (2.8.24)","version":"https://jsonfeed.org/version/1.1"}