Etruel develops the WPEmatico RSS Feed Fetcher plugin, a WordPress-focused content aggregation tool whose vulnerability footprint centers on web application input handling. The recurring exposure reflects the challenge of sanitizing and encoding dynamically fetched RSS content before rendering to end users, a pattern characteristic of aggregation and syndication plugins. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Etruel over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57349HIGH Unauthenticated Cross Site Scripting (XSS) in WPeMatico RSS Feed Fetcher <= 2.8.17 versions. | Jul 2, 2026 | 7.1 | 35 | NO | NO |
CVE-2025-11917MEDIUM The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.11 via the wpematico_test_feed() function | Nov 5, 2025 | 6.4 | 22 | NO | NO |
CVE-2021-24793MEDIUM The WPeMatico RSS Feed Fetcher WordPress plugin before 2.6.12 does not escape the Feed URL added to a campaign before outputting it in an attribute, allowing high privilege users t | Nov 1, 2021 | 4.8 | 18 | NO | NO |
CVE-2025-49922MEDIUM Missing Authorization vulnerability in etruel WPeMatico RSS Feed Fetcher wpematico allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPeMat | Oct 22, 2025 | 4.3 | 17 | NO | NO |
CVE-2025-57937MEDIUM Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in etruel WPeMatico RSS Feed Fetcher wpematico allows Retrieve Embedded Sensitive Data.This | Sep 22, 2025 | 4.3 | 17 | NO | NO |
CVE-2025-8103MEDIUM The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.7. This is due to missing nonce validation | Jul 26, 2025 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Etruel.
Media articles that mention a CVE ID that affects a product developed by Etruel — matched by CVE ID, not by vendor name.