WordPress Plugin Vulnerabilities

Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery

Description

The plugin does not validate the destination of a server-side request built from user-supplied input, allowing unauthenticated attackers to make the server issue requests to arbitrary hosts and read back responses that parse as RSS/XML.

Proof of Concept

Affects Plugins

Fixed in 8.3.1

References

Classification

Type
SSRF
OWASP top 10
CWE

Miscellaneous

Original Researcher
ApogeeBytes
Submitter
ApogeeBytes
Verified
Yes

Timeline

Publicly Published
2026-08-06 (about 4 days ago)
Added
2026-08-06 (about 3 days ago)
Last Updated
2026-08-06 (about 3 days ago)

Other