CVE-2026-97354: PowerPress 11.13.12 - 11.17.9 - Contributor+ SSRF via Media URL Redirects
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.11 does not validate the destination of redirects when fetching a user-supplied media URL, allowing users with the contributor role and above to perform Server-Side Request Forgery attacks against internal services.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated WordPress user with the Contributor role or any higher-privileged role can exploit it by supplying a media URL. Unauthenticated users are not indicated as able to exploit this issue.
What does exploitation require?
The attacker must be able to provide a media URL that causes a redirect. The vulnerable plugin follows that redirect without validating its destination, enabling requests to internal services.
Which versions are affected and what version fixes it?
PowerPress versions before 11.17.11 are affected; the reported affected range includes 11.13.12 through 11.17.9. Updating to version 11.17.11 or later addresses the issue.