CVE-2026-2216: Rachelos Werss We-Mp-Rss

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A flaw has been found in rachelos WeRSS we-mp-rss up to 1.4.8. Impacted is the function download_export_file of the file apis/tools.py. Executing a manipulation of the argument filename can lead to path traversal. The attack can be launched remotely. The exploit has been published and may be used.

Affected products

  • Rachelos Werss We-Mp-Rss: version 1.4.0 only; version 1.4.1 only; version 1.4.2 only; version 1.4.3 only; version 1.4.4 only; version 1.4.5 only; …

Published 2026-02-09. Last modified 2026-06-17.