Executive brief
The Podcast Player WordPress plugin before version 8.3.1 fails to validate podcast feed URLs supplied by users, allowing an attacker to force the server to fetch arbitrary RSS feeds and read back the results. This lets an attacker make the hosting server issue requests to internal services, external domains, or metadata endpoints that would normally be inaccessible, potentially exposing sensitive information or enabling lateral movement attacks on the hosting environment.
Technical details
The vulnerability is a Server-Side Request Forgery (SSRF) in the podcast feed URL parameter processing. The plugin's `pp_fetch_episodes` and `pp_search_episodes` AJAX actions accept a user-supplied `feedUrl` parameter and pass it directly to `wp_safe_remote_request()` without validating or sanitizing the destination. An unauthenticated attacker can extract the frontend nonce from any public page containing the podcast player, then send a specially crafted AJAX request to redirect the server to an arbitrary URL. The server fetches the target URL and parses the response as RSS/XML, returning matching episodes to the attacker. While WordPress's `wp_safe_remote_request()` blocks RFC1918 private ranges and loopback, external hosts and link-local addresses (e.g., 169.254.169.254) remain reachable. The vulnerability requires no authentication and affects the default plugin configuration. Fixed in version 8.3.1.
Affected products
- Podcast Player Podcast Player before 8.3.1
Timeline
- 2026-08-06: disclosed
- 2026-08-10: patched: Fixed in version 8.3.1