← volver
CVE-2026-97354mediumCWE-918

PowerPress 11.13.12 - 11.17.9 - Contributor+ SSRF via Media URL Redirects

10Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 4.1
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.11 does not validate the destination of redirects when fetching a user-supplied media URL, allowing users with the contributor role and above to perform Server-Side Request Forgery attacks against internal services.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N