Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Apogeebytes

#22784of 56,326
11.4Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-69345
5.3
2026-08-10
WordPress · The Podcast Player · CVE-2026-14860
**Name of the Vulnerable Software and Affected Versions** The Podcast Player versions prior to 8.3.1 **Description** The plugin fails to validate the destination of server-side requests constructed from user-supplied input. This allows unauthenticated attackers to force the server to send requests to arbitrary hosts and retrieve responses that are parsed as RSS/XML. This behavior is known as Server-Side Request Forgery (SSRF), where an attacker induces a server-side application to make requests to an unintended location. **Recommendations** Update The Podcast Player to version 8.3.1 or later.
PT-2026-66702
6.1
2026-07-31
WordPress · Newstatpress · CVE-2026-14845
**Name of the Vulnerable Software and Affected Versions** NewStatPress WordPress plugin versions prior to 1.4.5 **Description** Stored Cross-Site Scripting (XSS) occurs because the plugin fails to sanitize and escape data from unauthenticated visitor requests before storing it and subsequently displaying it within one of its widgets. This allows unauthenticated attackers to execute malicious scripts in the browsers of users who view the affected widget. **Recommendations** Update NewStatPress WordPress plugin to version 1.4.5 or later.