Server-Side Request Forgery in Podcast Player for WordPress
CVE-2026-14860
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 10 August 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-14860?
The Podcast Player WordPress plugin prior to version 8.3.1 is susceptible to server-side request forgery (SSRF) due to inadequate validation of user-supplied input. This flaw allows an unauthenticated attacker to manipulate server requests, enabling them to target arbitrary hosts and harvest responses formatted as RSS/XML. Successful exploitation could lead to unauthorized data exposure and further attacks against the server or other services it can access.
Affected Version(s)
Podcast Player 0 < 8.3.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.