Impact
The PowerPress Podcasting plugin fails to validate a Podcast Episode URL setting before using it in a server‑side request. This flaw allows an attacker with as little as Contributor role to instruct the plugin to query arbitrary URLs, potentially reaching internal services and exposing sensitive information or enabling further compromise.
Affected Systems
All instances of the Blubrry PowerPress Podcasting plugin running versions earlier than 11.17.1 on WordPress sites are affected. Users of sites that grant Contributor or similar roles to potentially untrusted users can exploit the vulnerability.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of < 1% shows a low likelihood of exploitation in the wild. This SSRF flaw allows the attacker to target internal services, potentially leading to network reconnaissance and data exfiltration. The lack of URL validation means any user with Contributor privileges can initiate successful requests. The overall impact depends on the host's network configuration and the sensitivity of the internal resources accessed.
OpenCVE Enrichment