← WordPress Vulnerabilities
WordPress security by component

PowerPress Podcasting plugin by Blubrry

PowerPress Podcasting plugin by Blubrry publishes, manages, and distributes podcasts from WordPress websites.

PowerPress Podcasting plugin by Blubrry (powerpress-podcasting-plugin-by-blubrry) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 6.8.

Plugin slug: powerpress-podcasting-plugin-by-blubrry

CVE-2026-16293: PowerPress episode settings permit Contributor stored XSS

PowerPress before 11.16.11 does not sanitize and escape some Podcast Episode settings before rendering them. A Contributor can store script-bearing setting values even when WordPress denies that role the unfiltered_html capability, causing JavaScript to execute when a user views the affected output. The public advisory does not disclose the settings, save endpoint, request parameters, renderer or exact audience that receives the stored payload.

PublishedAug 04, 2026
Known safe version11.16.11
Published vulnerabilities for powerpress-podcasting-plugin-by-blubrry
Safe version
Aug 04, 2026 CVE-2026-16293
PowerPress episode settings permit Contributor stored XSS
PowerPress before 11.16.11 does not sanitize and escape some Podcast Episode settings before rendering them. A Contributor can store script-bearing setting values even when WordPress denies that role the unfiltered_html capability, causing JavaScript to execute when a user views the affected output. The public advisory does not disclose the settings, save endpoint, request parameters, renderer or exact audience that receives the stored payload.
11.16.11
CVE6.8
NVDPending