
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24548 is a Server-Side Request Forgery (SSRF) vulnerability in the WordPress Radio Player plugin by princeahmed (also known as softlabbd). It affects all versions of the plugin up to and including 2.0.91, allowing unauthenticated remote attackers to induce the server to make requests to arbitrary external domains. The vulnerability was reported by Nabil Irawan on December 24, 2025, and publicly disclosed by Patchstack on January 23, 2026. It carries a CVSS v3.1 base score of 5.4 (Medium), assigned by Patchstack (Patchstack).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery) and maps to CAPEC-664. It arises from insufficient validation of user-supplied URLs or endpoints within the Radio Player plugin, enabling an unauthenticated attacker to craft requests that cause the WordPress server to fetch resources from attacker-controlled or internal network destinations. The attack vector is network-based, requires no authentication or user interaction, and has a changed scope, meaning the impact can extend beyond the vulnerable component itself. No public proof-of-concept code has been identified at this time (Patchstack).
Successful exploitation could allow an attacker to cause the WordPress server to issue HTTP requests to arbitrary internal or external hosts, potentially exposing sensitive information from internal services (e.g., cloud metadata endpoints, internal APIs) that are not directly accessible from the internet. The CVSS scope is marked as "Changed," indicating that the impact can extend to systems beyond the vulnerable WordPress instance. Confidentiality and integrity impacts are both rated Low, with no direct availability impact (Patchstack).
No confirmed in-the-wild exploitation has been reported for CVE-2026-24548. The EPSS score is approximately 0.017% (0.000170), indicating a very low probability of exploitation in the near term. The vulnerability requires no authentication, but the high attack complexity rating reduces its practical exploitability. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress plugins at scale, though this specific issue is rated low priority with unlikely exploitation impact. It does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack).
As of the disclosure date, no official patched version of the Radio Player plugin was available. Site administrators should monitor the WordPress plugin repository for an updated release beyond version 2.0.91 and apply it immediately when available. In the interim, disabling or removing the Radio Player plugin is the most effective workaround. Web application firewalls (WAFs) with SSRF detection rules, such as those provided by Patchstack's virtual patching, can provide interim protection. Restricting outbound HTTP requests from the WordPress server at the network/firewall level can also reduce the risk of SSRF exploitation (Patchstack).
Wordfence included CVE-2026-24548 in its weekly WordPress vulnerability report covering January 19–25, 2026, highlighting it as part of a broader set of plugin vulnerabilities disclosed that week (Wordfence). Patchstack, the CNA that assigned the CVE, rated the issue as low priority with unlikely exploitation impact, and no significant researcher commentary or media coverage beyond routine vulnerability tracking has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."