CVE Database /
CVE-2026-57349
CVE · High
CVE-2026-57349 — WPeMatico RSS Feed Fetcher [wpematico] < 2.8.18
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-57349
|
WPeMatico RSS Feed Fetcher [wpematico] < 2.8.18 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
High
7.1
|
< 2.8.18
|
2.8.18 |
2026-07-01 |
—
|
CVE-2026-57349
The WPeMatico RSS Feed Fetcher plugin for WordPress contains a security flaw that allows malicious code injection through unsanitized inputs, which can then be executed by users who visit affected pages. This vulnerability affects versions up to 2.8.17 and enables unauthenticated attackers to inject arbitrary web scripts into the system.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings