{"id":"CVE-2026-89001","title":"The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is permitted to publish content or to attribute posts to another account, allowing users with contributor-level access and …","summary":"The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is permitted to publish content or to attribute posts to another account, allowing users with contributor-level access and …","severity":"none","cwe":["CWE-269"],"product":"WPeMatico RSS Feed Fetcher","affected":["wpematico_rss_feed_fetcher < 2.8.27"],"published":"2026-09-27","updated":"2026-09-27","sourceUpdated":"2026-09-27T06:17:19.397","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89001","references":[{"url":"https://wpscan.com/vulnerability/829bfdc3-7a15-4d6a-9782-72d34fd114b7/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-27T06:43:46.831Z","slug":"CVE-2026-89001","body":"## Overview\n\nThe WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is permitted to publish content or to attribute posts to another account, allowing users with contributor-level access and above to publish posts live and set any registered user, including an administrator, as the post author.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}