All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-16294
HIGHpublished 2026-08-12 06:18 UTC · 21 hours ago · modified 2026-08-12 20:17 UTC
7.1
CVSS / 10
// description
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL settings before performing a server-side request with it, allowing users with a role as low as Contributor to perform Server-Side Request Forgery attacks that can target internal services.
// weaknesses (CWE)
- CWE-918