CVE Database /
CVE-2025-13031
CVE · Medium
CVE-2025-13031 — WPeMatico RSS Feed Fetcher [wpematico] < 2.8.13
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-13031
|
WPeMatico RSS Feed Fetcher [wpematico] < 2.8.13 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.9
|
< 2.8.13
|
2.8.13 |
2025-11-18 |
—
|
CVE-2025-13031
The WPeMatico RSS Feed Fetcher plugin for WordPress contains a security flaw affecting versions up to 2.8.12, which allows attackers with elevated privileges in certain environments to inject malicious code into pages accessed by users. This vulnerability arises from inadequate filtering of input data and insufficient protection against HTML injection. It specifically impacts multi-site setups where unfiltered HTML is restricted or disabled.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings