CVE-2026-24548

WordPress Radio Player plugin <= 2.0.91 - Server Side Request Forgery (SSRF) vulnerability

Server-Side Request Forgery (SSRF) vulnerability in Prince Radio Player radio-player allows Server Side Request Forgery.This issue affects Radio Player: from n/a through <= 2.0.91.


We have discovered 1,175 live websites that are affected by CVE-2026-24548.

Run a Free Instant Scan




Affected Software

Product  Radio Player
Category Wordpress Plugins
Vulnerable Domains1,175 live websites (100% of Radio Player install base)
Vulnerable Versions
  • from 0 through 2.0.91
Vulnerable Versions Count27 versions ( 100% of all versions)



Details

  • Published - Jan 23, 2026
  • Updated - Jan 26, 2026

Credits

  • Nabil Irawan | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-24548
United States323 websites



Germany103 websites
France63 websites
GB63 websites
Brazil61 websites
Italy52 websites
Argentina46 websites
Cyprus41 websites
Chile37 websites
Netherlands35 websites

Website Distribution by TLD

Number of websites using CVE-2026-24548
.com446 websites
.org91 websites
.com.br57 websites
.net44 websites
.it39 websites
.nl33 websites
.co.uk21 websites
.de20 websites
.es19 websites
.fr14 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-24548

Top websites that are affected by CVE-2026-24548. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com France***,***
********.org United States***,***
*********.info Russia***,***
**********************.com Canada***,***
**********.org United States***,***
***.***.et Ethiopia***,***
****.org United States*,***,***
**********.nl Netherlands*,***,***
******.***.br Brazil*,***,***
**************.pt Germany*,***,***
See full domain list

FAQ

A total of 1,175 websites have been identified as vulnerable to CVE-2026-24548, based on global website indexing conducted by WebTechSurvey.
The Radio Player is affected by the CVE-2026-24548 vulnerability.
Radio Player versions up to and including 2.0.91 are vulnerable to CVE-2026-24548.