{"id":"CVE-2026-89004","title":"The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returning a campaign's stored configuration and run log, allowing users with contributor-level access and above to read the c…","summary":"The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returning a campaign's stored configuration and run log, allowing users with contributor-level access and above to read the c…","severity":"low","cvss":2.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-639"],"product":"WPeMatico RSS Feed Fetcher","affected":["wpematico_rss_feed_fetcher < 2.8.26"],"published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T14:42:02.707","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89004","references":[{"url":"https://wpscan.com/vulnerability/1568f9e4-defe-423a-a631-e0afd829b972/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-24T10:34:02.613602Z"},"ingestedAt":"2026-09-24T06:39:26.615Z","slug":"CVE-2026-89004","body":"## Overview\n\nThe WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returning a campaign's stored configuration and run log, allowing users with contributor-level access and above to read the configuration and execution logs of campaigns created by other users, including administrators.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":15,"depthScoreParts":{"impact":14.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":210093,"id":"CVE-2026-89004","ts":1790250160743,"field":"cvss","old":null,"new":"2.7"},{"seq":210092,"id":"CVE-2026-89004","ts":1790250160743,"field":"severity","old":"none","new":"low"}]}