CVE-2026-89004 Overview
CVE-2026-89004 is a broken access control vulnerability in the WPeMatico RSS Feed Fetcher WordPress plugin before version 2.8.26. The plugin fails to verify ownership or authorization before returning a campaign's stored configuration and run log. Authenticated users with contributor-level access or above can read the configuration and execution logs of campaigns created by other users, including administrators. The flaw is classified under [CWE-639] (Authorization Bypass Through User-Controlled Key).
Critical Impact
Contributor-level accounts can retrieve WPeMatico campaign configurations and execution logs belonging to any other user, exposing feed sources, filter rules, and operational metadata authored by administrators.
Affected Products
- WPeMatico RSS Feed Fetcher WordPress plugin, versions prior to 2.8.26
- WordPress installations that grant contributor-level or higher access to untrusted users
- Multi-author WordPress sites using WPeMatico for content syndication
Discovery Timeline
- 2026-09-24 - CVE-2026-89004 published to the National Vulnerability Database
- 2026-09-24 - Last updated in NVD database
Technical Details for CVE-2026-89004
Vulnerability Analysis
The WPeMatico plugin exposes an internal handler that returns campaign configuration data and stored run logs when supplied with a campaign identifier. The handler enforces an authentication check but omits a check that ties the requested campaign to the requesting user. Any authenticated user with contributor privileges or higher can therefore request records belonging to other authors.
Campaign configuration typically contains feed URLs, credentials for remote sources, filter and rewrite rules, and scheduling data. Run logs contain execution timestamps, error strings, and processed item metadata. Exposure of this data assists reconnaissance and can leak information about internal automation that administrators configured.
Root Cause
The root cause is missing object-level authorization. The plugin trusts the campaign identifier passed in the request and returns the associated record without validating that the current user owns or is authorized to read it. This is a classic Insecure Direct Object Reference pattern captured by [CWE-639].
Attack Vector
Exploitation requires an authenticated session with contributor privileges or higher. The attacker issues a request to the plugin endpoint while iterating campaign identifiers assigned to other users. The server returns the stored configuration and run log for each valid identifier. No user interaction is required beyond the attacker's own request. Full technical details are documented in the WPScan Vulnerability Report.
Detection Methods for CVE-2026-89004
Indicators of Compromise
- Repeated requests from a single contributor account to WPeMatico campaign handlers with sequentially incrementing campaign identifiers
- Access to campaign records where the WordPress post_author does not match the requesting user's ID
- Unexpected reads of campaign log data by non-administrator accounts
Detection Strategies
- Enable WordPress access logging and correlate admin-ajax.php and REST API calls referencing WPeMatico actions with the authenticated user identifier
- Alert when contributor or author roles retrieve campaign objects owned by administrators
- Baseline normal plugin usage per role and flag deviations in request volume or identifier ranges
Monitoring Recommendations
- Ingest WordPress and web server logs into a SIEM and pivot on plugin endpoint URIs
- Track new or dormant contributor accounts that begin issuing plugin API requests
- Monitor outbound requests originating from the WordPress host that follow closely after configuration disclosures, which may indicate abuse of leaked feed credentials
How to Mitigate CVE-2026-89004
Immediate Actions Required
- Upgrade the WPeMatico RSS Feed Fetcher plugin to version 2.8.26 or later
- Audit contributor, author, and editor accounts and remove any that are not required
- Rotate any credentials or API keys stored in WPeMatico campaign configurations that may have been read by other users
Patch Information
The vendor addressed the missing authorization check in WPeMatico RSS Feed Fetcher version 2.8.26. Refer to the WPScan Vulnerability Report for the fixed version and vendor advisory links.
Workarounds
- Restrict contributor-level access to trusted users until the plugin is updated
- Remove sensitive credentials from campaign configurations and store them in server-side secrets where feasible
- Place the WordPress admin surface behind an IP allowlist or authenticated proxy to reduce the pool of accounts that can reach the vulnerable handler
# Configuration example
# Update WPeMatico via WP-CLI to the patched release
wp plugin update wpematico --version=2.8.26
wp plugin status wpematico
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
