---
id: CVE-2025-13031
title: >-
  The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.13 does not
  sanitize and escape some of its settings, which could allow high privilege
  users such as contributor to perform Stored Cross-Site Scripting attacks
summary: >-
  The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.13 does not
  sanitize and escape some of its settings, which could allow high privilege
  users such as contributor to perform Stored Cross-Site Scripting attacks
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'
published: '2025-12-09'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13031'
references:
  - url: 'https://wpscan.com/vulnerability/9bf76fed-8f0a-4aef-8cf4-f6839c8f0a53/'
    label: contact@wpscan.com
  - url: 'https://wpscan.com/vulnerability/9bf76fed-8f0a-4aef-8cf4-f6839c8f0a53/'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00224
epssPercentile: 0.11896
ingestedAt: '2026-10-07T20:46:46.784Z'
---

## Overview

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.13 does not sanitize and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
