CVE-2026-19883Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the wpematico_import_settings function in all versions up to, and including, 2.8.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • 5 total mentions across 1 day

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-08-22: 5Patch / Workaround · 2026-08-22: 2Technical Details · 2026-08-22: 408-22
Signal classification1 categories
Disclosure
5100.0%
Referenced assets3 URLs
Full discourse5 posts
  • ADK Cyber@ADKCyber
    Disclosure

    CVE-2026-19883 (CVSS 8.8) impacts the WPeMatico WordPress plugin with unauthorized data changes that can enable privilege escalation. Organizations using this plugin should verify and update immediately. via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/B6GxSM4PRJ

    Post summary

    The tweet discloses CVE-2026-19883, a high‑severity vulnerability in the WPeMatico WordPress plugin that allows unauthorized data changes and privilege escalation, and calls for immediate verification and update.

    0000030
    93 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    🚨🔐 NEW WORDPRESS PRIVILEGE-ESCALATION FLAW CAN TURN A BASIC SUBSCRIBER INTO AN ADMINISTRATOR CyberSignal Daily ✓ · WordPress Security · August 22, 2026 🎯 A high-severity vulnerability has been disclosed in the popular WPeMatico RSS Feed Fetcher plugin. 🔥 CVE-2026-19883 📊 CVSS: 8.8 / High Affected: 🔴 WPeMatico ≤ 2.8.24 The problem is a missing permission check around plugin configuration. An attacker only needs: 👤 a low-privilege WordPress account such as a: 🔑 Subscriber to modify site-level options they should never control. That can potentially allow them to: ⚙️ enable user registration ⬆️ change the default registration role 👑 create a new administrator account. 🧠 WHY THIS MATTERS WordPress security depends heavily on separating roles: Subscriber ≠ Editor ≠ Administrator. If a plugin exposes privileged configuration without verifying capabilities, that entire authorization model can collapse. The attack does not require an existing administrator account — only a low-level authenticated user. ⚠️ I found no confirmed active exploitation at this time. Administrators should update WPeMatico and review newly created users, role changes and unexpected registration settings. 🔗 Sources: Wordfence • CVE/NVD • WPeMatico #CyberSecurity #WordPress #WPeMatico #PrivilegeEscalation #CVE202619883 #AppSec #CyberNews

    Post summary

    A high‑severity privilege‑escalation flaw (CVE‑2026‑19883) in the WPeMatico plugin has been disclosed, with no signs of active exploitation; administrators are urged to update the plugin and audit site settings.

    0000060
    114 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19883 The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capabili… https://www.cve.org/CVERecord?id=CVE-2026-19883 ----- Traducción: CVE-2026-19883 El … http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-19883 as a privilege‑escalation flaw in the WPeMatico plugin, mentioning the vulnerability’s nature but offering no PoC, exploit code, patch, or active exploitation evidence.

    0000025
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19883 The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capabili… https://www.cve.org/CVERecord?id=CVE-2026-19883

    Post summary

    CVE‑2026‑19883 highlights a privilege‑escalation flaw in the WPeMatico WordPress plugin arising from missing capability checks, allowing unauthorized data modification.

    00000896
    58.0K followersView on X
  • SecNews@SecNews_GR
    Disclosure

    WPeMatico RSS: Κρίσιμη CVE-2026-19883 ανοίγει δρόμο για διαχειριστή https://secn.ws/Rp0WiY

    Post summary

    The snippet announces that CVE‑2026-19883 is a critical vulnerability in WPeMatico RSS, indicating it opens an administrative path, but it provides no technical details, exploitation proof, or mitigation information.

    00000197
    7.0K followersView on X

Explore more