What is CVE-2026-14860?
This CVE is a Server-Side Request Forgery (SSRF) vulnerability in The Podcast Player WordPress plugin before version 8.3.1. Unauthenticated attackers can exploit the lack of validation on the destination of server-side requests built from user-supplied input, allowing them to force the server to issue requests to arbitrary hosts and read responses that parse as RSS/XML. Updating to version 8.3.1 or later is strongly recommended.
Azərbaycanca: Bu CVE, The Podcast Player WordPress plaginin 8.3.1 versiyasından əvvəlki versiyalarında aşkar edilmiş Server-Side Request Forgery (SSRF) zəifliyidir. Autentifikasiya olunmamış hücumçular istifadəçi tərəfindən verilən məlumat əsasında qurulan server sorğusunun hədəfini təsdiqləməməkdən istifadə edərək, serveri istənilən hosta sorğu göndərməyə və RSS/XML formatında olan cavabları oxumağa məcbur edə bilər. Plaginin ən son 8.3.1 versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
What type of data can be read using the CVE-2026-14860 vulnerability?
The attacker can only read responses that parse as RSS/XML from the server-side requests they force.
To which version should The Podcast Player plugin be updated to protect against CVE-2026-14860?
It is recommended to update to version 8.3.1 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.