plugin

Powerpress Vulnerabilities

51 known security issues reported for the Powerpress WordPress plugin. Most recent disclosed Aug 14, 2026.

1 critical 4 high 21 medium

Running Powerpress on your site? Check whether your installed version is affected.

Scan your site free

PowerPress Podcasting plugin by Blubrry < 11.17.1 - Authenticated (Contributor+) Server-Side Request Forgery

medium

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to 11.17.1. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application which can...

CVSS:
6.4
Affected:
up to 11.17.1
Fixed in:
11.17.1
Disclosed:
Aug 14, 2026

CVE-2026-16294 on NVD →

Blubrry PowerPress <= 11.16.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 11.16.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in...

CVSS:
6.4
Affected:
up to 11.16.10
Fixed in:
11.16.11
Disclosed:
Jul 27, 2026

CVE-2026-16293 on NVD →

PowerPress Podcasting plugin by Blubrry <= 11.16.8 - Authenticated (Author+) Stored Cross-Site Scripting via 'embed' Episode Meta Field

medium

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed' Episode Meta Field in all versions up to, and including, 11.16.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level acc...

CVSS:
6.4
Affected:
up to 11.16.8
Fixed in:
11.16.9
Disclosed:
Jun 17, 2026

CVE-2026-12098 on NVD →

PowerPress Podcasting plugin by Blubrry <= 11.15.10 - Authenticated (Contributor+) SQL Injection

medium

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 11.15.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with co...

CVSS:
6.5
Affected:
up to 11.15.10
Fixed in:
11.15.11
Disclosed:
May 20, 2026

CVE-2026-24637 on NVD →

Blubrry PowerPress <= 11.15.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via powerpress and podcast Shortcodes

medium

The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'powerpress' and 'podcast' shortcodes in versions up to, and including, 11.15.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access...

CVSS:
6.4
Affected:
up to 11.15.15
Fixed in:
11.15.16
Disclosed:
Apr 7, 2026

CVE-2026-2988 on NVD →

PowerPress Podcasting plugin by Blubrry <= 11.15.10 - Authenticated (Contributor+) PHP Object Injection

high

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 11.15.10 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP...

CVSS:
7.5
Affected:
up to 11.15.10
Fixed in:
11.15.11
Disclosed:
Feb 25, 2026

CVE-2026-23798 on NVD →

PowerPress Podcasting <= 11.15.13 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The PowerPress Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 11.15.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pa...

CVSS:
6.4
Affected:
up to 11.15.13
Fixed in:
11.15.14
Disclosed:
Feb 13, 2026

CVE-2026-32351 on NVD →

PowerPress Podcasting plugin by Blubrry [powerpress] < 11.15.3

unknown

[en] The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 11.15.2. This is due to the plugin validating file extensions but not halting execution when validation fails in the 'powerpress_edit_post' function. Th...

Affected:
up to 11.15.3
Fixed in:
11.15.3
Disclosed:
Nov 27, 2025

CVE-2025-13536 on NVD →

Blubrry PowerPress <= 11.15.2 - Authenticated (Contributor+) Arbitrary File Upload via 'powerpress_edit_post'

high

The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 11.15.2. This is due to the plugin validating file extensions but not halting execution when validation fails in the 'powerpress_edit_post' function. This ma...

CVSS:
8.8
Affected:
up to 11.15.2
Fixed in:
11.15.3
Disclosed:
Nov 26, 2025

CVE-2025-13536 on NVD →

PowerPress Podcasting plugin by Blubrry [powerpress] <= 11.13.12 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in blubrry PowerPress Podcasting powerpress allows Cross Site Request Forgery.This issue affects PowerPress Podcasting: from n/a through <= 11.13.12.

Affected:
up to 11.13.12
Fix:
No patched version reported
Disclosed:
Oct 29, 2025

CVE-2025-64201 on NVD →

PowerPress Podcasting <= 11.13.12 - Cross-Site Request Forgery

medium

The PowerPress Podcasting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 11.13.12. This is due to missing or incorrect nonce validation on the 'powerpress-sync-progad' action. This makes it possible for unauthenticated attackers to perform an unauthorized action via a...

CVSS:
4.3
Affected:
up to 11.13.12
Fixed in:
11.14
Disclosed:
Oct 21, 2025

CVE-2025-64201 on NVD →

PowerPress Podcasting plugin by Blubrry [powerpress] <= 11.13.3 (unfixed)

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in Angelo Mandato PowerPress Podcasting allows Server Side Request Forgery. This issue affects PowerPress Podcasting: from n/a through 11.12.11.

Affected:
up to 11.13.3
Fix:
No patched version reported
Disclosed:
Jun 20, 2025

CVE-2025-49984 on NVD →

PowerPress Podcasting <= 11.13.11 - Authenticated (Contributor+) Server-Side Request Forgery

medium

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 11.13.11. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web...

CVSS:
6.4
Affected:
up to 11.13.11
Fixed in:
11.13.12
Disclosed:
Jun 19, 2025

CVE-2025-49984 on NVD →

PowerPress Podcasting plugin by Blubrry [powerpress] < 11.12.6

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in Angelo Mandato PowerPress Podcasting allows Upload a Web Shell to a Web Server. This issue affects PowerPress Podcasting: from n/a through 11.12.5.

Affected:
up to 11.12.6
Fixed in:
11.12.6
Disclosed:
Apr 24, 2025

CVE-2025-46264 on NVD →

PowerPress Podcasting plugin by Blubrry <= 11.12.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

high

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 11.12.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affect...

CVSS:
8.8
Affected:
up to 11.12.5
Fixed in:
11.12.6
Disclosed:
Apr 23, 2025

CVE-2025-46264 on NVD →

PowerPress Podcasting <= 11.12.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The PowerPress Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 11.12.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts i...

CVSS:
6.4
Affected:
up to 11.12.5
Fixed in:
11.12.6
Disclosed:
Apr 9, 2025

CVE-2025-32690 on NVD →

PowerPress Podcasting <= 11.12.6 - Authenticated (Contributor+) Server-Side Request Forgery

medium

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 11.12.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web a...

CVSS:
5.4
Affected:
up to 11.12.6
Fixed in:
11.12.7
Disclosed:
Apr 9, 2025

CVE-2025-32691 on NVD →

PowerPress Podcasting plugin by Blubrry [powerpress] < 11.12.7

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in Angelo Mandato PowerPress Podcasting allows Server Side Request Forgery. This issue affects PowerPress Podcasting: from n/a through 11.12.4.

Affected:
up to 11.12.7
Fixed in:
11.12.7
Disclosed:
Apr 9, 2025

CVE-2025-32691 on NVD →

PowerPress Podcasting plugin by Blubrry [powerpress] < 11.12.16

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Angelo Mandato PowerPress Podcasting allows DOM-Based XSS.This issue affects PowerPress Podcasting: from n/a through 11.12.5.

Affected:
up to 11.12.16
Fixed in:
11.12.16
Disclosed:
Apr 9, 2025

CVE-2025-32690 on NVD →

PowerPress Podcasting <= 11.9.17 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The PowerPress Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Podcast URLs in versions up to, and including, 11.9.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary w...

CVSS:
6.4
Affected:
up to 11.9.17
Fixed in:
11.9.18
Disclosed:
Mar 24, 2025

CVE-2024-9230 on NVD →

PowerPress Podcasting <= 11.9.17 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The PowerPress Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Podcast URLs in versions up to, and including, 11.9.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary w...

CVSS:
6.4
Affected:
up to 11.9.17
Fixed in:
11.9.18
Disclosed:
Mar 2, 2025

CVE-2024-9227 on NVD →

PowerPress Podcasting plugin by Blubrry [powerpress] < 11.9.19

unknown

[en] The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skipto' shortcode in all versions up to, and including, 11.9.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenti...

Affected:
up to 11.9.19
Fixed in:
11.9.19
Disclosed:
Oct 11, 2024

CVE-2024-9543 on NVD →

Powerpress <= 11.9.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via skipto Shortcode

medium

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skipto' shortcode in all versions up to, and including, 11.9.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...

CVSS:
6.4
Affected:
up to 11.9.18
Fixed in:
11.9.19
Disclosed:
Oct 10, 2024

CVE-2024-9543 on NVD →

PowerPress Podcasting plugin by Blubrry [powerpress] < 11.9.11

unknown

[en] The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘media_url’ parameter in all versions up to, and including, 11.9.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arb...

Affected:
up to 11.9.11
Fixed in:
11.9.11
Disclosed:
Jul 12, 2024

CVE-2024-6588 on NVD →

PowerPress Podcasting plugin by Blubrry <= 11.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via media_url Parameter

medium

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘media_url’ parameter in all versions up to, and including, 11.9.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar...

CVSS:
6.4
Affected:
up to 11.9.10
Fixed in:
11.9.11
Disclosed:
Jul 11, 2024

CVE-2024-6588 on NVD →

PowerPress Podcasting plugin by Blubrry [powerpress] < 11.9.5

unknown

[en] Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send tha...

Affected:
up to 11.9.5
Fixed in:
11.9.5
Disclosed:
Jun 25, 2024

CVE-2024-6297 on NVD →

Several WordPress.org Plugins <= Various Versions - Injected Backdoor

critical

Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that dat...

CVSS:
10
Affected:
11.9.3 – 11.9.4
Fixed in:
11.9.6
Disclosed:
Jun 24, 2024

CVE-2024-6297 on NVD →

PowerPress Podcasting plugin by Blubrry [powerpress] < 11.0.7

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in Blubrry PowerPress Podcasting plugin by Blubrry.This issue affects PowerPress Podcasting plugin by Blubrry: from n/a through 11.0.6.

Affected:
up to 11.0.7
Fixed in:
11.0.7
Disclosed:
Nov 13, 2023

CVE-2023-41239 on NVD →

PowerPress Podcasting plugin by Blubrry [powerpress] < 11.0.12

unknown

[en] The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.0.12 does not sanitize and escape the media url field in posts, which could allow users with privileges as low as contributor to inject arbitrary web scripts that could target a site admin or superadmin.

Affected:
up to 11.0.12
Fixed in:
11.0.12
Disclosed:
Oct 16, 2023

CVE-2023-4820 on NVD →

PowerPress Podcasting plugin by Blubrry [powerpress] < 11.0.11

unknown

Update the WordPress PowerPress Podcasting plugin to the latest available version (at least 11.0.11). Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress PowerPress Podcasting Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements...

Affected:
up to 11.0.11
Fixed in:
11.0.11
Disclosed:
Sep 15, 2023

PowerPress <= 11.0.11 - Authenticated(Contributor+) Stored Cross-Site Scripting via Media URL

medium

The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the media URL in versions up to, and including, 11.0.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permiss...

CVSS:
6.4
Affected:
up to 11.0.12
Fixed in:
11.0.12
Disclosed:
Sep 13, 2023

CVE-2023-4820 on NVD →

PowerPress Podcasting plugin by Blubrry [powerpress] < 11.0.11

unknown

The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the media URL in versions up to, and including, 11.0.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permiss...

Affected:
up to 11.0.11
Fixed in:
11.0.11
Disclosed:
Sep 13, 2023

PowerPress <= 11.0.6 - Authenticated (Contributor+) Server-Side Request Forgery via wp_ajax_powerpress_media_info

medium

The PowerPress plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 11.0.6 via the wp_ajax_powerpress_media_info AJAX action. This can allow authenticated attackers, with contributor-level permission and above, to make web requests to arbitrary locations originating from t...

CVSS:
5.4
Affected:
up to 11.0.6
Fixed in:
11.0.7
Disclosed:
Aug 29, 2023

CVE-2023-41239 on NVD →

PowerPress Podcasting plugin by Blubrry [powerpress] < 10.0.2

unknown

[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Blubrry PowerPress Podcasting plugin by Blubrry plugin <= 10.0.1 versions.

Affected:
up to 10.0.2
Fixed in:
10.0.2
Disclosed:
Aug 15, 2023

CVE-2023-30778 on NVD →

PowerPress Podcasting plugin by Blubrry [powerpress] < 10.0.1

unknown

[en] The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and...

Affected:
up to 10.0.1
Fixed in:
10.0.1
Disclosed:
Jun 9, 2023

CVE-2023-1917 on NVD →

PowerPress Podcasting plugin by Blubrry [powerpress] < 10.2.4

unknown

Update the WordPress PowerPress Podcasting plugin to the latest available version (at least 10.2.4). An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress PowerPress Podcasting Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, adver...

Affected:
up to 10.2.4
Fixed in:
10.2.4
Disclosed:
Jun 7, 2023

PowerPress <= 10.2.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Feed[title]'

medium

The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Feed[title]’ parameter in versions up to, and including, 10.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inj...

CVSS:
4.4
Affected:
up to 10.2.3
Fixed in:
10.2.4
Disclosed:
Jun 6, 2023

PowerPress Podcasting plugin by Blubrry [powerpress] < 10.2.4

unknown

The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Feed[title]’ parameter in versions up to, and including, 10.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inj...

Affected:
up to 10.2.4
Fixed in:
10.2.4
Disclosed:
Jun 6, 2023

PowerPress <= 10.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 10.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and ab...

CVSS:
5.4
Affected:
up to 10.0.1
Fixed in:
10.0.2
Disclosed:
Apr 17, 2023

CVE-2023-30778 on NVD →

PowerPress <= 10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and abov...

CVSS:
5.4
Affected:
up to 10.0
Fixed in:
10.0.2
Disclosed:
Apr 11, 2023

CVE-2023-1917 on NVD →

PowerPress Podcasting plugin by Blubrry [powerpress] < 8.6.2

unknown

Multiple Authenticated Cross-Site Scripting (XSS) vulnerabilities discovered by Lenon Leite in the WordPress PowerPress Podcasting plugin (versions <= 8.6.1).

Affected:
up to 8.6.2
Fixed in:
8.6.2
Disclosed:
May 14, 2021

PowerPress Podcasting plugin by Blubrry [powerpress] < 8.3.8

unknown

[en] Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.8, did not verify some of the uploaded feed images (such as the ones from Podcast Artwork section), allowing high privilege accounts (admin+) being able to upload arbitrary files, such as php, leading to RCE.

Affected:
up to 8.3.8
Fixed in:
8.3.8
Disclosed:
Mar 18, 2021

CVE-2021-24123 on NVD →

PowerPress <= 8.3.7 - Arbitrary File Upload

high

Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.7, did not verify some of the uploaded feed images (such as the ones from Podcast Artwork section), allowing high privilege accounts (admin+) being able to upload arbitrary files, such as php, leading to RCE.

CVSS:
7.2
Affected:
up to 8.3.7
Fixed in:
8.3.8
Disclosed:
Oct 11, 2020

CVE-2021-24123 on NVD →

PowerPress Podcasting plugin by Blubrry [powerpress] < 8.3.8

unknown

Authenticated Arbitrary File Upload leading to Remote Code Execution (RCE) vulnerability found by Minh Tuan (SunCSR) in WordPress PowerPress Podcasting plugin (versions <= 8.3.7).

Affected:
up to 8.3.8
Fixed in:
8.3.8
Disclosed:
Oct 11, 2020

PowerPress Podcasting plugin by Blubrry [powerpress] < 6.0.5

unknown

[en] The Blubrry PowerPress Podcasting plugin 6.0.4 for WordPress has XSS via the tab parameter.

Affected:
up to 6.0.5
Fixed in:
6.0.5
Disclosed:
Sep 25, 2019

CVE-2015-9410 on NVD →

PowerPress <= 6.0.4 - Reflected Cross-Site Scripting

medium

The Blubrry PowerPress Podcasting plugin 6.0.4 for WordPress has XSS via the tab parameter.

CVSS:
6.1
Affected:
up to 6.0.4
Fixed in:
6.0.5
Disclosed:
Sep 14, 2015

CVE-2015-9410 on NVD →

PowerPress Podcasting plugin by Blubrry [powerpress] < 6.0.5

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Upgrade the plugin.

Affected:
up to 6.0.5
Fixed in:
6.0.5
Disclosed:
Sep 14, 2015

PowerPress Podcasting plugin by Blubrry [powerpress] < 6.0.1

unknown

[en] Cross-site scripting (XSS) vulnerability in the Blubrry PowerPress Podcasting plugin before 6.0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cat parameter in a powerpress-editcategoryfeed action in the powerpressadmin_categoryfeeds.php page to wp-admin/admin.php.

Affected:
up to 6.0.1
Fixed in:
6.0.1
Disclosed:
Feb 2, 2015

CVE-2015-1385 on NVD →

PowerPress <= 6.0.0 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the Blubrry PowerPress Podcasting plugin before 6.0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cat parameter in a powerpress-editcategoryfeed action in the powerpressadmin_categoryfeeds.php page to wp-admin/admin.php.

CVSS:
6.1
Affected:
up to 6.0.0
Fixed in:
6.0.1
Disclosed:
Jan 29, 2015

CVE-2015-1385 on NVD →

PowerPress Podcasting plugin by Blubrry [powerpress] < 11.9.18

unknown
Affected:
up to 11.9.18
Fixed in:
11.9.18

CVE-2024-9227 on NVD →

PowerPress Podcasting plugin by Blubrry [powerpress] < 11.9.18

unknown
Affected:
up to 11.9.18
Fixed in:
11.9.18

CVE-2024-9230 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database