WordPress Plugin Vulnerabilities

Blubrry PowerPress < 11.17.1 - Contributor+ Server-Side Request Forgery via Podcast Episode Chapters URL

Description

The plugin does not validate one of its Podcast Episode URL settings before performing a server-side request with it, allowing users with a role as low as Contributor to perform Server-Side Request Forgery attacks that can target internal services.

Proof of Concept

Affects Plugins

Fixed in 11.17.1

References

Classification

Type
SSRF
OWASP top 10
CWE

Miscellaneous

Original Researcher
Meher Sudhakar Abbireddi
Submitter
Meher Sudhakar Abbireddi
Verified
Yes

Timeline

Publicly Published
2026-08-10 (about 2 days ago)
Added
2026-08-10 (about 1 day ago)
Last Updated
2026-08-10 (about 1 day ago)

Other