CVE-2025-8103
EUVD-2025-2277126.07.2025, 04:16
The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.7. This is due to missing nonce validation in the handle_feedback_submission() function. This makes it possible for unauthenticated attackers to deactivate the plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| etruel | wpematico_rss_feed_fetcher | 𝑥 ≤ 2.8.7 | CNA |
Common Weakness Enumeration
References