Impact
The vulnerability allows the PowerPress Podcasting plugin to send HTTP requests to arbitrary URLs supplied by an attacker, which can expose internal network resources or trigger unintended actions on internal services. This flaw falls under the SSRF weakness, enabling an attacker to read data or interact with services that should be inaccessible from the public internet.
Affected Systems
The issue affects the WordPress plugin blubrry PowerPress Podcasting when installed in any version through 11.13.11, with no specific sub‑versions identified as safe. Systems running these plugin versions and the associated WordPress environment are impacted.
Risk and Exploitability
The CVSS score of 4.9 indicates a moderate severity, while the EPSS score of less than 1% reflects a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV, suggesting it has not yet been observed in widespread attacks. Exploitation would require access to the WordPress admin area where the plugin configuration can be manipulated, allowing an attacker to supply a malicious URL that the plugin resolves server‑side.
OpenCVE Enrichment
EUVD