PowerPress Podcasting plugin by Blubrry
PowerPress Podcasting plugin by Blubrry publishes, manages, and distributes podcasts from WordPress websites.
PowerPress Podcasting plugin by Blubrry (powerpress-podcasting-plugin-by-blubrry) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 6.8.
powerpress-podcasting-plugin-by-blubrryCVE-2026-16293: PowerPress episode settings permit Contributor stored XSS
PowerPress before 11.16.11 does not sanitize and escape some Podcast Episode settings before rendering them. A Contributor can store script-bearing setting values even when WordPress denies that role the unfiltered_html capability, causing JavaScript to execute when a user views the affected output. The public advisory does not disclose the settings, save endpoint, request parameters, renderer or exact audience that receives the stored payload.
| Safe version |
|
||
|---|---|---|---|
| Aug 04, 2026 |
CVE-2026-16293
PowerPress episode settings permit Contributor stored XSS
PowerPress before 11.16.11 does not sanitize and escape some Podcast Episode settings before rendering them. A Contributor can store script-bearing setting values even when WordPress denies that role the unfiltered_html capability, causing JavaScript to execute when a user views the affected output. The public advisory does not disclose the settings, save endpoint, request parameters, renderer or exact audience that receives the stored payload.
|
11.16.11 |
CVE6.8
NVDPending
|