The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.13 does not sanitize and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks
References
Configurations
No configuration.
History
No history.
Information
Published : 2025-12-09 16:17
Updated : 2026-06-17 08:33
NVD link : CVE-2025-13031
Mitre link : CVE-2025-13031
CVE.ORG link : CVE-2025-13031
JSON object : View
Products Affected
No product.
CWE
No CWE.
