VYPR

PowerPress Podcasting plugin by Blubrry

by WordPress

CVEs (7)

  • CVE-2026-16294HigAug 12, 2026
    risk 0.46cvss 7.1epss 0.00

    The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL settings before performing a server-side request with it, allowing users with a role as low as Contributor to perform Server-Side Request Forgery attacks…

  • CVE-2024-9230MedApr 14, 2025
    risk 0.38cvss 5.9epss 0.00

    The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could allow author and above users to perform Stored Cross-Site Scripting attacks

  • CVE-2023-30778MedAug 15, 2023
    risk 0.36cvss 5.5epss 0.00

    Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Blubrry PowerPress Podcasting plugin by Blubrry plugin <= 10.0.1 versions.

  • CVE-2023-4820MedOct 16, 2023
    risk 0.35cvss 5.4epss 0.00

    The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.0.12 does not sanitize and escape the media url field in posts, which could allow users with privileges as low as contributor to inject arbitrary web scripts that could target a site admin or superadmin.

  • CVE-2015-9410MedSep 26, 2019
    risk 0.35cvss 5.4epss 0.01

    The Blubrry PowerPress Podcasting plugin 6.0.4 for WordPress has XSS via the tab parameter.

  • CVE-2024-9227MedMay 15, 2025
    risk 0.31cvss 4.8epss 0.00

    The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could allow admin users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is…

  • CVE-2026-16293MedAug 4, 2026
    risk 0.00cvss 6.8epss 0.00

    The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Podcast Episode settings, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html…