PowerPress Podcasting plugin by Blubrry
PowerPress Podcasting plugin by Blubrry adds podcast publishing, episode management, media feeds, player displays, and podcast subscription tools to WordPress.
PowerPress Podcasting plugin by Blubrry (powerpress) is a WordPress plugin with 22 published CVE records in this archive. The latest tracked vulnerability was published Aug 12, 2026; the highest published CVSS base score is 9.9.
powerpressCVE-2026-16294: PowerPress episode URLs give Contributors an SSRF primitive
PowerPress Podcasting before 11.17.1 lets a Contributor submit Powerpress[$FeedSlug][pci_chapters_url] in the podcast episode metabox. Save validation mistakenly checks a different chapterURL value and stores the unvalidated chapters URL. chapters_tab() later assigns that stored value to chapters_req_url and calls file_get_contents(), enabling server-side requests to internal services. The reachable schemes and ports, redirect and DNS behavior, and response-exfiltration depth are not disclosed.
| Safe version |
|
||
|---|---|---|---|
| Aug 12, 2026 |
CVE-2026-16294
PowerPress episode URLs give Contributors an SSRF primitive
PowerPress Podcasting before 11.17.1 lets a Contributor submit Powerpress[$FeedSlug][pci_chapters_url] in the podcast episode metabox. Save validation mistakenly checks a different chapterURL value and stores the unvalidated chapters URL. chapters_tab() later assigns that stored value to chapters_req_url and calls file_get_contents(), enabling server-side requests to internal services. The reachable schemes and ports, redirect and DNS behavior, and response-exfiltration depth are not disclosed.
|
11.17.1 |
CVE7.1
NVDPending
|
| Jun 18, 2026 |
CVE-2026-12098
PowerPress Podcasting plugin by Blubrry: Cross-site scripting
PowerPress Podcasting plugin by Blubrry is affected by cross-site scripting. Exploitation requires an authenticated author account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 11.16.8.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jun 15, 2026 |
CVE-2026-24637
PowerPress Podcasting: SQL injection
PowerPress Podcasting is affected by SQL injection. Exploitation requires an authenticated contributor account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 11.15.10.
|
11.15.11 |
CVE8.5
NVDPending
|
| Mar 13, 2026 |
CVE-2026-32351
PowerPress Podcasting: Cross-site scripting
PowerPress Podcasting is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Mar 05, 2026 |
CVE-2026-23798
PowerPress Podcasting: Code execution
PowerPress Podcasting is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Nov 27, 2025 |
CVE-2025-13536
Blubrry PowerPress: Dangerous file upload
Blubrry PowerPress is affected by dangerous file upload. Exploitation requires an authenticated contributor account. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Oct 29, 2025 |
CVE-2025-64201
PowerPress Podcasting: Cross-site request forgery
PowerPress Podcasting is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jun 20, 2025 |
CVE-2025-49984
PowerPress Podcasting: Server-side request forgery
PowerPress Podcasting is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE4.9
NVDPending
|
| May 15, 2025 |
CVE-2024-9227
PowerPress Podcasting plugin by Blubrry: Cross-site scripting
PowerPress Podcasting plugin by Blubrry is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| Apr 24, 2025 |
CVE-2025-46264
PowerPress Podcasting: Dangerous file upload
PowerPress Podcasting is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE9.9
NVDPending
|
| Apr 14, 2025 |
CVE-2024-9230
PowerPress Podcasting plugin by Blubrry: Cross-site scripting
PowerPress Podcasting plugin by Blubrry is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Apr 09, 2025 |
CVE-2025-32691
PowerPress Podcasting: Server-side request forgery
PowerPress Podcasting is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE4.9
NVDPending
|
| Apr 09, 2025 |
CVE-2025-32690
PowerPress Podcasting: Cross-site scripting
PowerPress Podcasting is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Oct 11, 2024 |
CVE-2024-9543
PowerPress Podcasting plugin by Blubrry: Cross-site scripting
PowerPress Podcasting plugin by Blubrry is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jul 12, 2024 |
CVE-2024-6588
PowerPress Podcasting plugin by Blubrry: Cross-site scripting
PowerPress Podcasting plugin by Blubrry is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Nov 13, 2023 |
CVE-2023-41239
PowerPress Podcasting plugin by Blubrry: Server-side request forgery
PowerPress Podcasting plugin by Blubrry is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE6.4
NVD6.5
|
| Oct 16, 2023 |
CVE-2023-4820
PowerPress Podcasting plugin by Blubrry: A security weakness
PowerPress Podcasting plugin by Blubrry is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Aug 15, 2023 |
CVE-2023-30778
Powerpress: Cross-site scripting
Powerpress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.5
NVD5.4
|
| Jun 09, 2023 |
CVE-2023-1917
PowerPress: Cross-site scripting
PowerPress is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Mar 18, 2021 |
CVE-2021-24123
PowerPress: Dangerous file upload
PowerPress is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVEPending
NVD7.2
|
| Sep 26, 2019 |
CVE-2015-9410
Powerpress: Cross-site scripting
Powerpress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD5.4
|
| Feb 02, 2015 |
CVE-2015-1385
Powerpress: Cross-site scripting
Powerpress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD4.3
|