AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-16294

HIGH · CVSS 7.1 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The PowerPress Podcasting plugin for WordPress versions prior to 11.17.1 is vulnerable due to insufficient validation of Podcast Episode URL settings, enabling users with Contributor roles to execute Server-Side Request Forgery (SSRF) attacks. This vulnerability could allow attackers to access internal services, potentially leading to data exposure or further exploitation of the server. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-16294
Severity
HIGH
CVSS
7.1
EPSS
0.17%
WordPress

Original NVD Description

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL settings before performing a server-side request with it, allowing users with a role as low as Contributor to perform Server-Side Request Forgery attacks that can target internal services.