Medium 4.3
2025-09-22< 2.8.11
WPeMatico RSS Feed Fetcher <= 2.8.10 - Authenticated (Subscriber+) Sensitive Information Exposure
Minimum safe version
2.8.13
Update to 2.8.13 or later to address 6 fixable vulnerabilities
WPeMatico RSS Feed Fetcher <= 2.8.10 - Authenticated (Subscriber+) Sensitive Information Exposure
CVE-2025-13031
CVE-2025-11917
CVE-2025-49922
WordPress WPeMatico RSS Feed Fetcher Plugin <= 2.8.7 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2021-24793