CVE-2026-89000 Overview
CVE-2026-89000 is a Server-Side Request Forgery (SSRF) vulnerability in the WPeMatico RSS Feed Fetcher WordPress plugin before version 2.8.27. The plugin fetches user-supplied feed URLs server-side without performing a capability check or validating the destination of the request. Authenticated users with contributor-level access or above can direct the WordPress server to issue HTTP requests to internal-only resources and read the responses. This exposes internal services, cloud metadata endpoints, and other network resources that are not reachable from the public internet. The flaw is categorized under [CWE-918].
Critical Impact
Contributor-level users can abuse the plugin's feed fetcher to probe internal networks and retrieve responses from otherwise unreachable services.
Affected Products
- WPeMatico RSS Feed Fetcher WordPress plugin versions prior to 2.8.27
- WordPress installations with contributor-level or higher user accounts
- Any hosting environment where the WordPress server has access to internal network resources
Discovery Timeline
- 2026-09-27 - CVE-2026-89000 published to NVD
- 2026-09-28 - Last updated in NVD database
Technical Details for CVE-2026-89000
Vulnerability Analysis
The WPeMatico RSS Feed Fetcher plugin accepts a feed URL from the user and performs a server-side HTTP request to retrieve the feed content. The plugin returns the response to the requesting user. Two independent flaws combine to produce the SSRF condition. First, the feed-fetching endpoint lacks a capability check appropriate to the sensitivity of the action. Second, the plugin does not validate the destination of the supplied URL against an allowlist or deny internal address ranges.
An attacker with a contributor account can submit URLs targeting 127.0.0.1, 169.254.169.254, RFC1918 ranges, or internal hostnames. The server performs the request from its own network position and returns the response body to the attacker. This enables reconnaissance of internal services, retrieval of cloud instance metadata, and interaction with unauthenticated internal APIs.
Root Cause
The root cause is missing authorization enforcement combined with absent destination validation on the feed URL input. The handler trusts contributor-level users for an action that functions as an outbound HTTP proxy. No filtering is applied to prevent requests to loopback, link-local, or private network ranges.
Attack Vector
Exploitation requires an authenticated contributor-level WordPress account on a site running a vulnerable version of the plugin. The attacker submits a crafted feed URL pointing to an internal resource through the plugin's normal feed-add workflow. The WordPress server fetches the URL and returns the response, which the attacker reads through the plugin interface. Refer to the WPScan Vulnerability Report for additional technical details.
Detection Methods for CVE-2026-89000
Indicators of Compromise
- Outbound HTTP requests from the WordPress server to internal IP ranges (127.0.0.0/8, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) originating from PHP processes
- Requests to cloud metadata endpoints such as 169.254.169.254 from the web server
- Entries in WordPress logs showing feed-add actions by contributor accounts targeting unusual hostnames
Detection Strategies
- Review WPeMatico plugin logs and WordPress audit logs for feed URL submissions targeting non-standard or internal destinations
- Correlate web application access logs with outbound firewall logs to identify server-initiated requests to internal services
- Monitor for contributor accounts performing feed-fetching actions at unusual rates or against unusual targets
Monitoring Recommendations
- Instrument egress monitoring on web server hosts to flag connections to RFC1918 and link-local address ranges
- Alert on any PHP-initiated requests to cloud metadata service IP addresses
- Enable WordPress user activity logging to track feed-related operations by non-administrator accounts
How to Mitigate CVE-2026-89000
Immediate Actions Required
- Update the WPeMatico RSS Feed Fetcher plugin to version 2.8.27 or later on all affected WordPress installations
- Audit contributor-level and higher user accounts for legitimacy and remove unnecessary accounts
- Review recent feed fetch activity for signs of SSRF probing against internal resources
Patch Information
Upgrade WPeMatico RSS Feed Fetcher to version 2.8.27 or later. The patched release adds the missing capability check and validates the destination of user-supplied feed URLs. See the WPScan Vulnerability Report for advisory details.
Workarounds
- Restrict contributor-level accounts on affected sites until the plugin is updated
- Deploy egress filtering at the network layer to block web server requests to internal address ranges and cloud metadata endpoints
- Temporarily disable the WPeMatico plugin on production sites that cannot be patched immediately
# Example egress restriction using iptables to block metadata endpoint
iptables -A OUTPUT -m owner --uid-owner www-data -d 169.254.169.254 -j REJECT
iptables -A OUTPUT -m owner --uid-owner www-data -d 127.0.0.0/8 ! -o lo -j REJECT
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.