WordPress Plugin Vulnerabilities
Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery
Description
The plugin does not validate the destination of a server-side request built from user-supplied input, allowing unauthenticated attackers to make the server issue requests to arbitrary hosts and read back responses that parse as RSS/XML.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
SSRF
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
ApogeeBytes
Submitter
ApogeeBytes
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-06 (about 4 days ago)
Added
2026-08-06 (about 3 days ago)
Last Updated
2026-08-06 (about 3 days ago)