CVE-2020-24149: Secondline Podcast Importer Secondline

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

Server-side request forgery (SSRF) in the Podcast Importer SecondLine (podcast-importer-secondline) plugin 1.1.4 for WordPress via the podcast_feed parameter in a secondline_import_initialize action to the secondlinepodcastimport page.

Affected products

  • Secondline Podcast Importer Secondline: version 1.1.4 only

Published 2021-07-07. Last modified 2026-06-17.