Description
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL settings before performing a server-side request with it, allowing users with a role as low as Contributor to perform Server-Side Request Forgery attacks that can target internal services.
Published: 2026-08-12
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The PowerPress Podcasting plugin fails to validate a Podcast Episode URL setting before using it in a server‑side request. This flaw allows an attacker with as little as Contributor role to instruct the plugin to query arbitrary URLs, potentially reaching internal services and exposing sensitive information or enabling further compromise.

Affected Systems

All instances of the Blubrry PowerPress Podcasting plugin running versions earlier than 11.17.1 on WordPress sites are affected. Users of sites that grant Contributor or similar roles to potentially untrusted users can exploit the vulnerability.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity, while the EPSS score of < 1% shows a low likelihood of exploitation in the wild. This SSRF flaw allows the attacker to target internal services, potentially leading to network reconnaissance and data exfiltration. The lack of URL validation means any user with Contributor privileges can initiate successful requests. The overall impact depends on the host's network configuration and the sensitivity of the internal resources accessed.

Generated by OpenCVE AI on August 13, 2026 at 01:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PowerPress to version 11.17.1 or later to apply the vendor patch addressing the URL validation flaw.
  • Restrict Contributor or similar roles to the least necessary permissions, or revoke contributor privileges from untrusted users until the plugin is updated.
  • Implement outbound request filtering or network segmentation to block internal addresses from being queried by WordPress plugins, thereby limiting the impact of any future SSRF exploitation.

Generated by OpenCVE AI on August 13, 2026 at 01:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Blubrry
Blubrry powerpress Podcasting Plugin By Blubrry
Wordpress
Wordpress wordpress
Vendors & Products Blubrry
Blubrry powerpress Podcasting Plugin By Blubrry
Wordpress
Wordpress wordpress

Wed, 12 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Wed, 12 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL settings before performing a server-side request with it, allowing users with a role as low as Contributor to perform Server-Side Request Forgery attacks that can target internal services.
Title Blubrry PowerPress < 11.17.1 - Contributor+ Server-Side Request Forgery via Podcast Episode Chapters URL
References

Subscriptions

Blubrry Powerpress Podcasting Plugin By Blubrry
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-12T19:29:57.353Z

Reserved: 2026-07-20T12:29:06.556Z

Link: CVE-2026-16294

cve-icon Vulnrichment

Updated: 2026-08-12T19:29:53.980Z

cve-icon NVD

Status : Deferred

Published: 2026-08-12T06:18:55.203

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-16294

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:30:04Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)