CVE-2026-97354 PUBLISHED

PowerPress 11.13.12 - 11.17.9 - Contributor+ SSRF via Media URL Redirects

Assigner: WPScan
Reserved: 24.09.2026 Published: 07.10.2026 Updated: 07.10.2026

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.11 does not validate the destination of redirects when fetching a user-supplied media URL, allowing users with the contributor role and above to perform Server-Side Request Forgery attacks against internal services.

Product Status

Vendor Unknown
Product PowerPress Podcasting plugin by Blubrry
Versions Default: unaffected
  • affected from 11.13.12 to 11.17.11 (excl.)

Credits

  • Raj Ukani finder
  • WPScan coordinator

References

Problem Types

  • CWE-918 Server-Side Request Forgery (SSRF) CWE