Description
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL settings before performing a server-side request with it, allowing users with a role as low as Contributor to perform Server-Side Request Forgery attacks that can target internal services.
Published: 2026-08-12
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The PowerPress Podcasting plugin fails to validate a Podcast Episode URL setting before using it in a server‑side request. This flaw allows an attacker with as little as Contributor role to instruct the plugin to query arbitrary URLs, potentially reaching internal services and exposing sensitive information or enabling further compromise.

Affected Systems

All instances of the Blubrry PowerPress Podcasting plugin running versions earlier than 11.17.1 on WordPress sites are affected. Users of sites that grant Contributor or similar roles to potentially untrusted users can exploit the vulnerability.

Risk and Exploitability

While an EPSS score is not available and the issue is not listed in the CISA KEV catalog, the nature of SSRF defects generally permits internal network reconnaissance and data exfiltration. The absence of input validation increases the likelihood of successful exploitation by Anyone with Contributor privileges. The exact severity depends on the network configuration of the affected host.

Generated by OpenCVE AI on August 12, 2026 at 12:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PowerPress to version 11.17.1 or later to apply the vendor patch addressing the URL validation flaw.
  • Restrict Contributor or similar roles to the least necessary permissions, or revoke contributor privileges from untrusted users until the plugin is updated.
  • Implement outbound request filtering or network segmentation to block internal addresses from being queried by WordPress plugins, thereby limiting the impact of any future SSRF exploitation.

Generated by OpenCVE AI on August 12, 2026 at 12:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL settings before performing a server-side request with it, allowing users with a role as low as Contributor to perform Server-Side Request Forgery attacks that can target internal services.
Title Blubrry PowerPress < 11.17.1 - Contributor+ Server-Side Request Forgery via Podcast Episode Chapters URL
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-12T06:00:15.176Z

Reserved: 2026-07-20T12:29:06.556Z

Link: CVE-2026-16294

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-12T06:18:55.203

Modified: 2026-08-12T06:18:55.203

Link: CVE-2026-16294

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T12:30:03Z

Weaknesses

No weakness.