Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Blubrry
Blubrry powerpress Podcasting Plugin By Blubrry Wordpress Wordpress wordpress |
|
| Vendors & Products |
Blubrry
Blubrry powerpress Podcasting Plugin By Blubrry Wordpress Wordpress wordpress |
Wed, 12 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-918 | |
| Metrics |
cvssV3_1
|
Wed, 12 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL settings before performing a server-side request with it, allowing users with a role as low as Contributor to perform Server-Side Request Forgery attacks that can target internal services. | |
| Title | Blubrry PowerPress < 11.17.1 - Contributor+ Server-Side Request Forgery via Podcast Episode Chapters URL | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-12T19:29:57.353Z
Reserved: 2026-07-20T12:29:06.556Z
Link: CVE-2026-16294
Updated: 2026-08-12T19:29:53.980Z
Status : Received
Published: 2026-08-12T06:18:55.203
Modified: 2026-08-12T20:17:37.453
Link: CVE-2026-16294
No data.
OpenCVE Enrichment
Updated: 2026-08-13T10:30:04Z