CVE-2026-14860: Podcast Player < 8.3.1 - Unauthenticated Server-Side Request Forgery
The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from user-supplied input, allowing unauthenticated attackers to make the server issue requests to arbitrary hosts and read back responses that parse as RSS/XML.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14860?
The severity of CVE-2026-14860 is rated at 62, indicating a significant risk due to potential server-side request forgery.
How do I fix CVE-2026-14860?
To fix CVE-2026-14860, upgrade to the Podcast Player WordPress plugin version 8.3.1 or later, which addresses the vulnerability.
What type of vulnerability is CVE-2026-14860?
CVE-2026-14860 is categorized as an unauthenticated server-side request forgery (SSRF) vulnerability.
Who is affected by CVE-2026-14860?
Any users of the Podcast Player WordPress plugin prior to version 8.3.1 are affected by CVE-2026-14860.
What can attackers do with CVE-2026-14860?
Attackers can exploit CVE-2026-14860 to make the server issue requests to arbitrary hosts and potentially read sensitive responses.