Description
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.11 does not validate the destination of redirects when fetching a user-supplied media URL, allowing users with the contributor role and above to perform Server-Side Request Forgery attacks against internal services.
Published: 2026-10-07
Score: n/a
EPSS: n/a
KEV: No
Impact: Server‑Side Request Forgery enabling access to internal services via unvalidated media URL redirects
Action: Apply patch
AI Analysis

Impact

The PowerPress Podcasting plugin fails to validate the target of redirects when retrieving a user‑supplied media URL. This flaw allows a user with the contributor role or higher to instruct the WordPress instance to resolve the URL and follow any redirect chain, resulting in requests to arbitrary internal network locations. The attacker can therefore read or interact with services that are normally inaccessible from the public internet, compromising confidentiality and potentially integrity of internal resources. The weakness corresponds to the Server‑Side Request Forgery class of vulnerabilities.

Affected Systems

Blubrry PowerPress Podcasting plugin for WordPress, any release prior to version 11.17.11 – including the 11.13.12 through 11.17.9 range. Users running these versions are impacted unless the contributor functionality has been removed or restricted.

Risk and Exploitability

There is no published CVSS score or EPSS value in the current data, and the vulnerability is not listed in the CISA KEV catalog. The risk stems from the requirement of a contributor role; therefore, an attacker must obtain or impersonate such a user. Once in position, exploitation is straightforward: the plugin fetches the supplied media URL and follows redirects without destination checks, enabling outbound requests to any internal address. The lack of a public exploit or exploit code in the data suggests low to moderate exploitation likelihood, but the potential for internal network exposure remains high for affected installations.

Generated by OpenCVE AI on October 7, 2026 at 07:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the PowerPress plugin to version 11.17.11 or later to obtain the SSRF fix
  • If updating is not immediately possible, remove contributor or higher users’ ability to add media URLs through plugin settings or role‑based permission changes
  • Deploy an outbound request filter or firewall rule in the hosting environment to block or log HTTP requests originating from the WordPress installation to internal network addresses

Generated by OpenCVE AI on October 7, 2026 at 07:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Wed, 07 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.11 does not validate the destination of redirects when fetching a user-supplied media URL, allowing users with the contributor role and above to perform Server-Side Request Forgery attacks against internal services.
Title PowerPress 11.13.12 - 11.17.9 - Contributor+ SSRF via Media URL Redirects
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-07T06:00:09.174Z

Reserved: 2026-09-24T12:37:26.878Z

Link: CVE-2026-97354

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T07:17:02.870

Modified: 2026-10-07T07:17:02.870

Link: CVE-2026-97354

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T07:30:14Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)