What is CVE-2026-16294?
The PowerPress Podcasting plugin by Blubrry before version 11.17.1 contains a Server-Side Request Forgery (SSRF) vulnerability due to improper validation of a Podcast Episode URL setting. This allows authenticated users with roles as low as Contributor to target internal network resources. Updating the plugin to the latest version is strongly recommended.
Azərbaycanca: PowerPress Podcasting plugin-in 11.17.1-dən əvvəlki versiyalarında server tərəfli sorğu saxtakarlığı (SSRF) zəifliyi aşkarlanıb. Bu zəiflik Contributor kimi aşağı səlahiyyətli istifadəçilərə belə daxili şəbəkə resurslarına müdaxilə etməyə imkan verir. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of the PowerPress Podcasting plugin are affected by the CVE-2026-16294 SSRF vulnerability?
Versions of the PowerPress Podcasting plugin before 11.17.1 are affected.
What is the minimum user role required to exploit this vulnerability?
An authenticated user with a role as low as Contributor can exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.