WordPress · The Podcast Player · CVE-2026-14860
**Name of the Vulnerable Software and Affected Versions**
The Podcast Player versions prior to 8.3.1
**Description**
The plugin fails to validate the destination of server-side requests constructed from user-supplied input. This allows unauthenticated attackers to force the server to send requests to arbitrary hosts and retrieve responses that are parsed as RSS/XML. This behavior is known as Server-Side Request Forgery (SSRF), where an attacker induces a server-side application to make requests to an unintended location.
**Recommendations**
Update The Podcast Player to version 8.3.1 or later.