Impact
The PowerPress Podcasting plugin fails to validate the target of redirects when retrieving a user‑supplied media URL. This flaw allows a user with the contributor role or higher to instruct the WordPress instance to resolve the URL and follow any redirect chain, resulting in requests to arbitrary internal network locations. The attacker can therefore read or interact with services that are normally inaccessible from the public internet, compromising confidentiality and potentially integrity of internal resources. The weakness corresponds to the Server‑Side Request Forgery class of vulnerabilities.
Affected Systems
Blubrry PowerPress Podcasting plugin for WordPress, any release prior to version 11.17.11 – including the 11.13.12 through 11.17.9 range. Users running these versions are impacted unless the contributor functionality has been removed or restricted.
Risk and Exploitability
There is no published CVSS score or EPSS value in the current data, and the vulnerability is not listed in the CISA KEV catalog. The risk stems from the requirement of a contributor role; therefore, an attacker must obtain or impersonate such a user. Once in position, exploitation is straightforward: the plugin fetches the supplied media URL and follows redirects without destination checks, enabling outbound requests to any internal address. The lack of a public exploit or exploit code in the data suggests low to moderate exploitation likelihood, but the potential for internal network exposure remains high for affected installations.
OpenCVE Enrichment