CVE-2025-32691: WordPress PowerPress Podcasting plugin <= 11.12.6 - Server Side Request Forgery (SSRF) Vulnerability
Server-Side Request Forgery (SSRF) vulnerability in Angelo Mandato PowerPress Podcasting allows Server Side Request Forgery. This issue affects PowerPress Podcasting: from n/a through 11.12.4.
Other sources
Server-Side Request Forgery (SSRF) vulnerability in blubrry PowerPress Podcasting powerpress allows Server Side Request Forgery.This issue affects PowerPress Podcasting: from n/a through <= 11.12.6.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32691?
CVE-2025-32691 is classified as a medium-severity Server-Side Request Forgery (SSRF) vulnerability.
How do I fix CVE-2025-32691?
To fix CVE-2025-32691, upgrade PowerPress Podcasting to version 11.12.5 or later, which addresses the vulnerability.
Which versions of PowerPress Podcasting are affected by CVE-2025-32691?
CVE-2025-32691 affects all versions of PowerPress Podcasting from n/a through 11.12.4.
What type of vulnerability is CVE-2025-32691?
CVE-2025-32691 is a Server-Side Request Forgery (SSRF) vulnerability that allows attackers to send unauthorized requests from the server.
Who is the vendor associated with CVE-2025-32691?
The vendor associated with CVE-2025-32691 is Angelo Mandato, the creator of PowerPress Podcasting.