CVE-2026-16294: Blubrry PowerPress < 11.17.1 - Contributor+ Server-Side Request Forgery via Podcast Episode Chapters URL
Published Aug 12, 2026
·Updated
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL settings before performing a server-side request with it, allowing users with a role as low as Contributor to perform Server-Side Request Forgery attacks that can target internal services.
Affected Software
1 affected component
Blubrry PowerPress<11.17.1
Event History
Aug 12, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:18 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-16294?
The severity of CVE-2026-16294 is rated as 56.
2
What type of vulnerability is CVE-2026-16294?
CVE-2026-16294 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
3
How do I fix CVE-2026-16294?
To fix CVE-2026-16294, update the Blubrry PowerPress plugin to version 11.17.1 or later.
4
Who is affected by CVE-2026-16294?
Users with a Contributor role or higher are affected by CVE-2026-16294.
5
What plugin is associated with CVE-2026-16294?
CVE-2026-16294 is associated with the Blubrry PowerPress plugin for WordPress.