CVE-2026-97354
- EPSS 0.18%
- Veröffentlicht 07.10.2026 06:00:09
- Zuletzt bearbeitet 07.10.2026 14:52:43
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.11 does not validate the destination of redirects when fetching a user-supplied media URL, allowing users with the contributor role and above to perform Server-Side Request For...
CVE-2026-104388
- EPSS 0.23%
- Veröffentlicht 05.10.2026 08:56:48
- Zuletzt bearbeitet 06.10.2026 15:04:25
Missing Authorization vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Retrieve Embedded Sensitive Data.This issue affects PowerPress Podcasting: from n/a through 11.17.9.
CVE-2026-104407
- EPSS 0.1%
- Veröffentlicht 05.10.2026 08:35:02
- Zuletzt bearbeitet 06.10.2026 15:04:25
Cross-Site Request Forgery (CSRF) vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Cross Site Request Forgery.This issue affects PowerPress Podcasting: from n/a through 11.17.9.
CVE-2026-16294
- EPSS 0.17%
- Veröffentlicht 12.08.2026 06:00:15
- Zuletzt bearbeitet 26.08.2026 16:30:52
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL settings before performing a server-side request with it, allowing users with a role as low as Contributor to perform Server-...
CVE-2026-16293
- EPSS 0.15%
- Veröffentlicht 04.08.2026 06:00:12
- Zuletzt bearbeitet 26.08.2026 16:31:16
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Podcast Episode settings, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks e...
CVE-2026-24637
- EPSS 0.25%
- Veröffentlicht 15.06.2026 20:17:31
- Zuletzt bearbeitet 15.06.2026 21:24:32
Contributor SQL Injection in PowerPress Podcasting <= 11.15.10 versions.
CVE-2026-2988
- EPSS 0.21%
- Veröffentlicht 08.04.2026 02:25:40
- Zuletzt bearbeitet 25.07.2026 10:10:00
The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'powerpress' and 'podcast' shortcodes in versions up to, and including, 11.15.15 due to insufficient input sanitization and output escaping. This makes i...
CVE-2025-13536
- EPSS 0.58%
- Veröffentlicht 27.11.2025 08:27:05
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 11.15.2. This is due to the plugin validating file extensions but not halting execution...
CVE-2024-9227
- EPSS 0.31%
- Veröffentlicht 15.05.2025 20:16:00
- Zuletzt bearbeitet 05.06.2025 14:21:12
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could allow admin users to perform Stored Cross-Site Scripting attacks even when the unfiltered...
CVE-2024-9230
- EPSS 0.25%
- Veröffentlicht 14.04.2025 06:00:04
- Zuletzt bearbeitet 29.04.2025 20:33:55
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could allow author and above users to perform Stored Cross-Site Scripting attacks