ConicPlex

Start Your Project

A laptop glowing with abstract WordPress-blue dashboard light next to an orange RSS feed icon pin and a blank keycard on a wooden desk

On this Page

WPeMatico RSS Feed Fetcher Patches Four Flaws That Let Contributors Hijack Posts (CVE-2026-89000, CVE-2026-89001)

WPeMatico RSS Feed Fetcher shipped version 2.8.27 on September 22, 2026, fixing four vulnerabilities (CVE-2026-89000, CVE-2026-89001, CVE-2026-89002, CVE-2026-89003) that let Contributor-level accounts trigger SSRF and fake post authorship.

Aftab Memon

September 27, 2026

WPeMatico, the WordPress plugin more than 10,000 sites use to auto-import content from RSS feeds, shipped version 2.8.27 on September 22, 2026, patching four vulnerabilities that let Contributor-level accounts overreach their role. Two are server-side request forgery bugs (CVE-2026-89000 and CVE-2026-89003) that let a low-privilege user make the server fetch internal-only addresses. A third, CVE-2026-89001, lets a Contributor publish a post live and credit it to any registered user, including an administrator. WordPress.org flags the release as a recommended security update.

What the four bugs actually let a Contributor do

WPeMatico’s entire job is fetching remote feed URLs and turning them into posts, so the plugin already talks to arbitrary web addresses on the server’s behalf. CVE-2026-89000 and CVE-2026-89003 exist because it never checked whether that destination was a genuine public feed or an internal address in disguise. According to WPScan’s advisory for CVE-2026-89000, a Contributor account, the same role many sites hand to guest writers or freelance content contributors, could point a campaign at an internal-only host and read back whatever the server received in response. Both SSRF flaws carry a WPScan-rated CVSS of 4.1.

CVE-2026-89001 is the more useful bug for an actual attacker. WPScan rates it 4.9 and describes a plugin that never verified a campaign runner was permitted to publish content or attribute it to someone else. A Contributor could run a feed campaign, have the resulting post go live without an editorial review step, and set the byline to any registered account, up to and including an admin.

A fourth issue, CVE-2026-89002, is a stored XSS bug WPScan rates 6.8, the highest severity of the group, though it was actually closed a version earlier in 2.8.26. It let a Contributor’s imported feed content run unsanitized script against whoever reviewed the campaign afterward, usually an editor or admin.

Who should care, and what to do

This matters most on sites that hand the Contributor role to people outside the core team: guest writers, freelance content contributors, or junior staff who submit posts for review before anything publishes. That’s exactly the trust boundary WPeMatico’s bugs erase.

  • Update WordPress plugin WPeMatico to version 2.8.27 or later right away.
  • Review which accounts currently hold the Contributor role and whether they still need it.
  • Check recently published posts for authorship that doesn’t match who actually wrote them.

For agencies running multiple client sites with a mix of guest contributors and in-house writers, this is exactly the kind of gap a plugin audit is built to catch before a routine update cycle quietly does it for you. It’s also a reminder that WordPress’s own auto-blocking of high-risk plugin updates only stops the worst cases, not every contributor-level bug that slips through review.

Sources

Aftab Memon is a Senior WordPress Developer at ConicPlex, working across everything from plugin conflicts and theme customization to full site builds on Elementor and WooCommerce. He spends most of his time in the parts of WordPress that don’t show up in a features list: hosting quirks, hook priority, the difference between a plugin that works in isolation and one that survives a real production stack. He writes here about what actually holds up once a WordPress site is live and being run by a non-technical client, not just what works in a demo.

Leave a Reply

Your email address will not be published. Required fields are marked *

Keep reading

Plugins

Illustration of a shield with a checkmark, empty OTP verification boxes, and a phone, representing OTP verification at WooCommerce checkout

How to Verify Phone Numbers with OTP to Stop Fake WooCommerce Orders (3 Plugins Compared)

SMS Alert, Blacklist Manager, and Customer Email Verification for WooCommerce compared: setup steps, pricing, and where each plugin’s free tier…

Sajil Memon

September 27, 2026

News & Updates

A server unit being connected to a network switch in a violet-lit server room, with an access badge and a small elephant charm on the workbench, evoking PHP security patches

PHP Patches a FastCGI ACL Bypass and TLS Verification Flaw in Every Supported Branch (CVE-2026-91768, CVE-2026-91769)

PHP 8.5.11, 8.4.26, 8.3.35, and 8.2.34 patch a FastCGI IPv6 ACL bypass and a TLS hostname verification flaw, plus eight…

Sajil Memon

September 26, 2026

Plugins

Illustration of a torn ticket stub representing a WooCommerce deposit, split between a paid purple portion and an unpaid outlined portion, with a coin token overlapping the corner

Best WooCommerce Deposit and Partial Payment Plugins: 3 Real Options Compared

A WooCommerce deposit plugin lets a customer pay part of an order now and the rest later, useful for custom-made…

Sajil Memon

September 26, 2026

WhatsApp
Husen Memon
Husen Memon
Typically replies instant