S4E just found a critical-severity finding from cve-2022-27924 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 14, 2025

CVE-2024-54385 Scanner

CVE-2024-54385 Scanner - Server-Side Request Forgery vulnerability in Radio Player

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-54385
7.2
CVSShigh
Exploitable remotely over the internet · no authentication required.

Server-Side Request Forgery (SSRF) vulnerability in princeahmed Radio Player radio-player allows Server Side Request Forgery.This issue affects Radio Player: from n/a through <= 2.0.83.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Radio Playerby princeahmed
0
Updated Sep 10, 2026View on NVD →
Detail

The Radio Player plugin for WordPress is widely used to integrate live audio streams such as Shoutcast and Icecast into websites. It is designed for web administrators and developers aiming to deliver a seamless audio experience to users. With features like customizable players and broad compatibility, this plugin simplifies the process of embedding live streams on WordPress sites.

The vulnerability detected is a Server-Side Request Forgery (SSRF). This flaw allows attackers to manipulate the web server to make unauthorized requests to arbitrary locations. Exploiting this vulnerability can lead to querying and modifying sensitive data from internal services.

The technical details of this vulnerability involve a vulnerable endpoint that processes unauthenticated requests. The "radio_player_get_stream_data" action parameter, combined with a crafted URL, enables attackers to trigger unauthorized requests via server-side communication. The affected parameters include nonce and url fields in HTTP POST requests.

Exploitation of this vulnerability can lead to sensitive data leakage, manipulation of internal services, and potential pivoting into more critical systems. Malicious users could misuse it for reconnaissance or privilege escalation.

REFERENCES

Solution Advice
  • Update the Radio Player plugin to the latest patched version to eliminate the vulnerability.
  • Restrict network access to sensitive endpoints to prevent unauthorized queries.
  • Enable input validation and sanitization for user-provided data in HTTP requests.
  • Implement server-side controls to validate and restrict outbound requests.
  • Monitor network logs for unusual request patterns originating from the plugin.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-54385 Scanner - Server-Side Request Forgery vulnerability in Radio Player <= 2.0.82 | S4E