PT-2026-69345 · WordPress · The Podcast Player
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The Podcast Player versions prior to 8.3.1
Description
The plugin fails to validate the destination of server-side requests constructed from user-supplied input. This allows unauthenticated attackers to force the server to send requests to arbitrary hosts and retrieve responses that are parsed as RSS/XML. This behavior is known as Server-Side Request Forgery (SSRF), where an attacker induces a server-side application to make requests to an unintended location.
Recommendations
Update The Podcast Player to version 8.3.1 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Podcast Player