Impact
The PowerPress Podcasting plugin fails to validate a Podcast Episode URL setting before using it in a server‑side request. This flaw allows an attacker with as little as Contributor role to instruct the plugin to query arbitrary URLs, potentially reaching internal services and exposing sensitive information or enabling further compromise.
Affected Systems
All instances of the Blubrry PowerPress Podcasting plugin running versions earlier than 11.17.1 on WordPress sites are affected. Users of sites that grant Contributor or similar roles to potentially untrusted users can exploit the vulnerability.
Risk and Exploitability
While an EPSS score is not available and the issue is not listed in the CISA KEV catalog, the nature of SSRF defects generally permits internal network reconnaissance and data exfiltration. The absence of input validation increases the likelihood of successful exploitation by Anyone with Contributor privileges. The exact severity depends on the network configuration of the affected host.
OpenCVE Enrichment