Description
Unauthenticated Server Side Request Forgery (SSRF) in StreamCast <= 2.4.5 versions.
Published: 2026-10-10
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Server Side Request Forgery that allows unauthenticated users to cause the server to send arbitrary HTTP requests to internal or external resources.
Action: Apply Update
AI Analysis

Impact

The vulnerability is a Server Side Request Forgery (SSRF) that does not require authentication; an attacker can submit crafted requests to the affected endpoint and cause the WordPress site to initiate requests to arbitrary destinations. This can expose internal network services, retrieve sensitive data from internal hosts, or provide an attack surface for further exploitation. The issue is identified as CWE‑918 and is rated with a CVSS score of 7.2, indicating a moderate to high severity.

Affected Systems

The affected product is the WordPress StreamCast plugin provided by bPlugins, with version numbers up to 2.4.5 susceptible to this flaw. Any WordPress installation running one of these versions is potentially vulnerable.

Risk and Exploitability

With a CVSS of 7.2 the vulnerability represents a serious risk; the EPSS score is not available, and it is not listed in CISA’s KEV catalog. The attack vector is inferred to be server‑side, requiring only a user‑initiated request to the vulnerable endpoint, as authentication is not needed. Because the SSRF can target arbitrary URLs, the attacker could access private IP ranges or internal resources, which could lead to data exposure or further compromise. The overall risk is moderate to high and should be addressed promptly.

Generated by OpenCVE AI on October 10, 2026 at 20:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update StreamCast to the latest patched version (≥ 2.4.6 if available).
  • If an update is not immediately possible, disable the StreamCast plugin or remove its endpoints from the public URL space.
  • Configure the web application firewall or network policies to block outbound traffic from the WordPress hosting environment to private IP ranges (e.g., 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) and to restrict communication to only known, trusted external destinations.

Generated by OpenCVE AI on October 10, 2026 at 20:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Server Side Request Forgery (SSRF) in StreamCast <= 2.4.5 versions.
Title WordPress StreamCast plugin <= 2.4.5 - Server Side Request Forgery (SSRF) vulnerability
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T19:35:30.447Z

Reserved: 2026-07-13T06:14:28.261Z

Link: CVE-2026-62030

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T20:16:39.110

Modified: 2026-10-10T20:16:39.110

Link: CVE-2026-62030

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T20:45:17Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)