The WPeMatico RSS Feed Fetcher plugin for WordPress contains a missing capability check on the wpematico_import_settings function. This vulnerability affects all versions up to and including 2.8.24. Authenticated attackers with subscriber-level access or above can exploit this flaw to modify arbitrary WordPress site options. The vulnerability can be leveraged to change the default registration role to administrator and enable open user registration. This effectively allows attackers to create administrator-level accounts and gain full control of the WordPress site. The vulnerability is classified as an unauthorized data modification issue leading to privilege escalation. A patch has been committed to the plugin repository addressing the missing capability check.