---
id: CVE-2026-89006
title: >-
  The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not
  sanitize imported feed content before storing it as post content, allowing
  users with the Contributor role and above to perform Stored Cross-Site
  Scripting attacks.
summary: >-
  The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not
  sanitize imported feed content before storing it as post content, allowing
  users with the Contributor role and above to perform Stored Cross-Site
  Scripting attacks.
severity: none
cwe:
  - CWE-79
product: WPeMatico RSS Feed Fetcher
affected:
  - wpematico_rss_feed_fetcher < 2.8.27
published: '2026-09-27'
updated: '2026-09-27'
sourceUpdated: '2026-09-27T06:17:22.377'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89006'
references:
  - url: 'https://wpscan.com/vulnerability/680091de-610a-4665-a028-515ca6c33055/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-27T06:43:46.832Z'
---

## Overview

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not sanitize imported feed content before storing it as post content, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
