PowerPress Podcasting plugin by Blubrry < 11.17.1 - Authenticated (Contributor+) Server-Side Request Forgery
medium
The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to 11.17.1. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application which can...
- CVSS:
- 6.4
- Affected:
- up to 11.17.1
- Fixed in:
- 11.17.1
- Disclosed:
- Aug 14, 2026
CVE-2026-16294 on NVD →
Blubrry PowerPress <= 11.16.10 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 11.16.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in...
- CVSS:
- 6.4
- Affected:
- up to 11.16.10
- Fixed in:
- 11.16.11
- Disclosed:
- Jul 27, 2026
CVE-2026-16293 on NVD →
PowerPress Podcasting plugin by Blubrry <= 11.16.8 - Authenticated (Author+) Stored Cross-Site Scripting via 'embed' Episode Meta Field
medium
The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed' Episode Meta Field in all versions up to, and including, 11.16.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level acc...
- CVSS:
- 6.4
- Affected:
- up to 11.16.8
- Fixed in:
- 11.16.9
- Disclosed:
- Jun 17, 2026
CVE-2026-12098 on NVD →
PowerPress Podcasting plugin by Blubrry <= 11.15.10 - Authenticated (Contributor+) SQL Injection
medium
The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 11.15.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with co...
- CVSS:
- 6.5
- Affected:
- up to 11.15.10
- Fixed in:
- 11.15.11
- Disclosed:
- May 20, 2026
CVE-2026-24637 on NVD →
Blubrry PowerPress <= 11.15.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via powerpress and podcast Shortcodes
medium
The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'powerpress' and 'podcast' shortcodes in versions up to, and including, 11.15.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access...
- CVSS:
- 6.4
- Affected:
- up to 11.15.15
- Fixed in:
- 11.15.16
- Disclosed:
- Apr 7, 2026
CVE-2026-2988 on NVD →
PowerPress Podcasting plugin by Blubrry <= 11.15.10 - Authenticated (Contributor+) PHP Object Injection
high
The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 11.15.10 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP...
- CVSS:
- 7.5
- Affected:
- up to 11.15.10
- Fixed in:
- 11.15.11
- Disclosed:
- Feb 25, 2026
CVE-2026-23798 on NVD →
PowerPress Podcasting <= 11.15.13 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The PowerPress Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 11.15.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pa...
- CVSS:
- 6.4
- Affected:
- up to 11.15.13
- Fixed in:
- 11.15.14
- Disclosed:
- Feb 13, 2026
CVE-2026-32351 on NVD →
PowerPress Podcasting plugin by Blubrry [powerpress] < 11.15.3
unknown
[en] The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 11.15.2. This is due to the plugin validating file extensions but not halting execution when validation fails in the 'powerpress_edit_post' function. Th...
- Affected:
- up to 11.15.3
- Fixed in:
- 11.15.3
- Disclosed:
- Nov 27, 2025
CVE-2025-13536 on NVD →
Blubrry PowerPress <= 11.15.2 - Authenticated (Contributor+) Arbitrary File Upload via 'powerpress_edit_post'
high
The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 11.15.2. This is due to the plugin validating file extensions but not halting execution when validation fails in the 'powerpress_edit_post' function. This ma...
- CVSS:
- 8.8
- Affected:
- up to 11.15.2
- Fixed in:
- 11.15.3
- Disclosed:
- Nov 26, 2025
CVE-2025-13536 on NVD →
PowerPress Podcasting plugin by Blubrry [powerpress] <= 11.13.12 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in blubrry PowerPress Podcasting powerpress allows Cross Site Request Forgery.This issue affects PowerPress Podcasting: from n/a through <= 11.13.12.
- Affected:
- up to 11.13.12
- Fix:
- No patched version reported
- Disclosed:
- Oct 29, 2025
CVE-2025-64201 on NVD →
PowerPress Podcasting <= 11.13.12 - Cross-Site Request Forgery
medium
The PowerPress Podcasting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 11.13.12. This is due to missing or incorrect nonce validation on the 'powerpress-sync-progad' action. This makes it possible for unauthenticated attackers to perform an unauthorized action via a...
- CVSS:
- 4.3
- Affected:
- up to 11.13.12
- Fixed in:
- 11.14
- Disclosed:
- Oct 21, 2025
CVE-2025-64201 on NVD →
PowerPress Podcasting plugin by Blubrry [powerpress] <= 11.13.3 (unfixed)
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Angelo Mandato PowerPress Podcasting allows Server Side Request Forgery. This issue affects PowerPress Podcasting: from n/a through 11.12.11.
- Affected:
- up to 11.13.3
- Fix:
- No patched version reported
- Disclosed:
- Jun 20, 2025
CVE-2025-49984 on NVD →
PowerPress Podcasting <= 11.13.11 - Authenticated (Contributor+) Server-Side Request Forgery
medium
The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 11.13.11. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web...
- CVSS:
- 6.4
- Affected:
- up to 11.13.11
- Fixed in:
- 11.13.12
- Disclosed:
- Jun 19, 2025
CVE-2025-49984 on NVD →
PowerPress Podcasting plugin by Blubrry [powerpress] < 11.12.6
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Angelo Mandato PowerPress Podcasting allows Upload a Web Shell to a Web Server. This issue affects PowerPress Podcasting: from n/a through 11.12.5.
- Affected:
- up to 11.12.6
- Fixed in:
- 11.12.6
- Disclosed:
- Apr 24, 2025
CVE-2025-46264 on NVD →
PowerPress Podcasting plugin by Blubrry <= 11.12.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
high
The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 11.12.5. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affect...
- CVSS:
- 8.8
- Affected:
- up to 11.12.5
- Fixed in:
- 11.12.6
- Disclosed:
- Apr 23, 2025
CVE-2025-46264 on NVD →
PowerPress Podcasting <= 11.12.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The PowerPress Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 11.12.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts i...
- CVSS:
- 6.4
- Affected:
- up to 11.12.5
- Fixed in:
- 11.12.6
- Disclosed:
- Apr 9, 2025
CVE-2025-32690 on NVD →
PowerPress Podcasting <= 11.12.6 - Authenticated (Contributor+) Server-Side Request Forgery
medium
The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 11.12.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web a...
- CVSS:
- 5.4
- Affected:
- up to 11.12.6
- Fixed in:
- 11.12.7
- Disclosed:
- Apr 9, 2025
CVE-2025-32691 on NVD →
PowerPress Podcasting plugin by Blubrry [powerpress] < 11.12.7
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Angelo Mandato PowerPress Podcasting allows Server Side Request Forgery. This issue affects PowerPress Podcasting: from n/a through 11.12.4.
- Affected:
- up to 11.12.7
- Fixed in:
- 11.12.7
- Disclosed:
- Apr 9, 2025
CVE-2025-32691 on NVD →
PowerPress Podcasting plugin by Blubrry [powerpress] < 11.12.16
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Angelo Mandato PowerPress Podcasting allows DOM-Based XSS.This issue affects PowerPress Podcasting: from n/a through 11.12.5.
- Affected:
- up to 11.12.16
- Fixed in:
- 11.12.16
- Disclosed:
- Apr 9, 2025
CVE-2025-32690 on NVD →
PowerPress Podcasting <= 11.9.17 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The PowerPress Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Podcast URLs in versions up to, and including, 11.9.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary w...
- CVSS:
- 6.4
- Affected:
- up to 11.9.17
- Fixed in:
- 11.9.18
- Disclosed:
- Mar 24, 2025
CVE-2024-9230 on NVD →
PowerPress Podcasting <= 11.9.17 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The PowerPress Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Podcast URLs in versions up to, and including, 11.9.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary w...
- CVSS:
- 6.4
- Affected:
- up to 11.9.17
- Fixed in:
- 11.9.18
- Disclosed:
- Mar 2, 2025
CVE-2024-9227 on NVD →
PowerPress Podcasting plugin by Blubrry [powerpress] < 11.9.19
unknown
[en] The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skipto' shortcode in all versions up to, and including, 11.9.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenti...
- Affected:
- up to 11.9.19
- Fixed in:
- 11.9.19
- Disclosed:
- Oct 11, 2024
CVE-2024-9543 on NVD →
Powerpress <= 11.9.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via skipto Shortcode
medium
The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skipto' shortcode in all versions up to, and including, 11.9.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- CVSS:
- 6.4
- Affected:
- up to 11.9.18
- Fixed in:
- 11.9.19
- Disclosed:
- Oct 10, 2024
CVE-2024-9543 on NVD →
PowerPress Podcasting plugin by Blubrry [powerpress] < 11.9.11
unknown
[en] The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘media_url’ parameter in all versions up to, and including, 11.9.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arb...
- Affected:
- up to 11.9.11
- Fixed in:
- 11.9.11
- Disclosed:
- Jul 12, 2024
CVE-2024-6588 on NVD →
PowerPress Podcasting plugin by Blubrry <= 11.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via media_url Parameter
medium
The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘media_url’ parameter in all versions up to, and including, 11.9.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar...
- CVSS:
- 6.4
- Affected:
- up to 11.9.10
- Fixed in:
- 11.9.11
- Disclosed:
- Jul 11, 2024
CVE-2024-6588 on NVD →
PowerPress Podcasting plugin by Blubrry [powerpress] < 11.9.5
unknown
[en] Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send tha...
- Affected:
- up to 11.9.5
- Fixed in:
- 11.9.5
- Disclosed:
- Jun 25, 2024
CVE-2024-6297 on NVD →
Several WordPress.org Plugins <= Various Versions - Injected Backdoor
critical
Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that dat...
- CVSS:
- 10
- Affected:
- 11.9.3 – 11.9.4
- Fixed in:
- 11.9.6
- Disclosed:
- Jun 24, 2024
CVE-2024-6297 on NVD →
PowerPress Podcasting plugin by Blubrry [powerpress] < 11.0.7
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Blubrry PowerPress Podcasting plugin by Blubrry.This issue affects PowerPress Podcasting plugin by Blubrry: from n/a through 11.0.6.
- Affected:
- up to 11.0.7
- Fixed in:
- 11.0.7
- Disclosed:
- Nov 13, 2023
CVE-2023-41239 on NVD →
PowerPress Podcasting plugin by Blubrry [powerpress] < 11.0.12
unknown
[en] The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.0.12 does not sanitize and escape the media url field in posts, which could allow users with privileges as low as contributor to inject arbitrary web scripts that could target a site admin or superadmin.
- Affected:
- up to 11.0.12
- Fixed in:
- 11.0.12
- Disclosed:
- Oct 16, 2023
CVE-2023-4820 on NVD →
PowerPress Podcasting plugin by Blubrry [powerpress] < 11.0.11
unknown
Update the WordPress PowerPress Podcasting plugin to the latest available version (at least 11.0.11).
Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress PowerPress Podcasting Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements...
- Affected:
- up to 11.0.11
- Fixed in:
- 11.0.11
- Disclosed:
- Sep 15, 2023
PowerPress <= 11.0.11 - Authenticated(Contributor+) Stored Cross-Site Scripting via Media URL
medium
The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the media URL in versions up to, and including, 11.0.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permiss...
- CVSS:
- 6.4
- Affected:
- up to 11.0.12
- Fixed in:
- 11.0.12
- Disclosed:
- Sep 13, 2023
CVE-2023-4820 on NVD →
PowerPress Podcasting plugin by Blubrry [powerpress] < 11.0.11
unknown
The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the media URL in versions up to, and including, 11.0.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permiss...
- Affected:
- up to 11.0.11
- Fixed in:
- 11.0.11
- Disclosed:
- Sep 13, 2023
PowerPress <= 11.0.6 - Authenticated (Contributor+) Server-Side Request Forgery via wp_ajax_powerpress_media_info
medium
The PowerPress plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 11.0.6 via the wp_ajax_powerpress_media_info AJAX action. This can allow authenticated attackers, with contributor-level permission and above, to make web requests to arbitrary locations originating from t...
- CVSS:
- 5.4
- Affected:
- up to 11.0.6
- Fixed in:
- 11.0.7
- Disclosed:
- Aug 29, 2023
CVE-2023-41239 on NVD →
PowerPress Podcasting plugin by Blubrry [powerpress] < 10.0.2
unknown
[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Blubrry PowerPress Podcasting plugin by Blubrry plugin <= 10.0.1 versions.
- Affected:
- up to 10.0.2
- Fixed in:
- 10.0.2
- Disclosed:
- Aug 15, 2023
CVE-2023-30778 on NVD →
PowerPress Podcasting plugin by Blubrry [powerpress] < 10.0.1
unknown
[en] The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and...
- Affected:
- up to 10.0.1
- Fixed in:
- 10.0.1
- Disclosed:
- Jun 9, 2023
CVE-2023-1917 on NVD →
PowerPress Podcasting plugin by Blubrry [powerpress] < 10.2.4
unknown
Update the WordPress PowerPress Podcasting plugin to the latest available version (at least 10.2.4).
An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress PowerPress Podcasting Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, adver...
- Affected:
- up to 10.2.4
- Fixed in:
- 10.2.4
- Disclosed:
- Jun 7, 2023
PowerPress <= 10.2.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Feed[title]'
medium
The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Feed[title]’ parameter in versions up to, and including, 10.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inj...
- CVSS:
- 4.4
- Affected:
- up to 10.2.3
- Fixed in:
- 10.2.4
- Disclosed:
- Jun 6, 2023
PowerPress Podcasting plugin by Blubrry [powerpress] < 10.2.4
unknown
The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Feed[title]’ parameter in versions up to, and including, 10.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inj...
- Affected:
- up to 10.2.4
- Fixed in:
- 10.2.4
- Disclosed:
- Jun 6, 2023
PowerPress <= 10.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 10.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and ab...
- CVSS:
- 5.4
- Affected:
- up to 10.0.1
- Fixed in:
- 10.0.2
- Disclosed:
- Apr 17, 2023
CVE-2023-30778 on NVD →
PowerPress <= 10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and abov...
- CVSS:
- 5.4
- Affected:
- up to 10.0
- Fixed in:
- 10.0.2
- Disclosed:
- Apr 11, 2023
CVE-2023-1917 on NVD →
PowerPress Podcasting plugin by Blubrry [powerpress] < 8.6.2
unknown
Multiple Authenticated Cross-Site Scripting (XSS) vulnerabilities discovered by Lenon Leite in the WordPress PowerPress Podcasting plugin (versions <= 8.6.1).
- Affected:
- up to 8.6.2
- Fixed in:
- 8.6.2
- Disclosed:
- May 14, 2021
PowerPress Podcasting plugin by Blubrry [powerpress] < 8.3.8
unknown
[en] Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.8, did not verify some of the uploaded feed images (such as the ones from Podcast Artwork section), allowing high privilege accounts (admin+) being able to upload arbitrary files, such as php, leading to RCE.
- Affected:
- up to 8.3.8
- Fixed in:
- 8.3.8
- Disclosed:
- Mar 18, 2021
CVE-2021-24123 on NVD →
PowerPress <= 8.3.7 - Arbitrary File Upload
high
Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.7, did not verify some of the uploaded feed images (such as the ones from Podcast Artwork section), allowing high privilege accounts (admin+) being able to upload arbitrary files, such as php, leading to RCE.
- CVSS:
- 7.2
- Affected:
- up to 8.3.7
- Fixed in:
- 8.3.8
- Disclosed:
- Oct 11, 2020
CVE-2021-24123 on NVD →
PowerPress Podcasting plugin by Blubrry [powerpress] < 8.3.8
unknown
Authenticated Arbitrary File Upload leading to Remote Code Execution (RCE) vulnerability found by Minh Tuan (SunCSR) in WordPress PowerPress Podcasting plugin (versions <= 8.3.7).
- Affected:
- up to 8.3.8
- Fixed in:
- 8.3.8
- Disclosed:
- Oct 11, 2020
PowerPress Podcasting plugin by Blubrry [powerpress] < 6.0.5
unknown
[en] The Blubrry PowerPress Podcasting plugin 6.0.4 for WordPress has XSS via the tab parameter.
- Affected:
- up to 6.0.5
- Fixed in:
- 6.0.5
- Disclosed:
- Sep 25, 2019
CVE-2015-9410 on NVD →
PowerPress <= 6.0.4 - Reflected Cross-Site Scripting
medium
The Blubrry PowerPress Podcasting plugin 6.0.4 for WordPress has XSS via the tab parameter.
- CVSS:
- 6.1
- Affected:
- up to 6.0.4
- Fixed in:
- 6.0.5
- Disclosed:
- Sep 14, 2015
CVE-2015-9410 on NVD →
PowerPress Podcasting plugin by Blubrry [powerpress] < 6.0.5
unknown
Because of this vulnerability, the attackers can inject arbitrary web script or HTML.
Upgrade the plugin.
- Affected:
- up to 6.0.5
- Fixed in:
- 6.0.5
- Disclosed:
- Sep 14, 2015
PowerPress Podcasting plugin by Blubrry [powerpress] < 6.0.1
unknown
[en] Cross-site scripting (XSS) vulnerability in the Blubrry PowerPress Podcasting plugin before 6.0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cat parameter in a powerpress-editcategoryfeed action in the powerpressadmin_categoryfeeds.php page to wp-admin/admin.php.
- Affected:
- up to 6.0.1
- Fixed in:
- 6.0.1
- Disclosed:
- Feb 2, 2015
CVE-2015-1385 on NVD →
PowerPress <= 6.0.0 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the Blubrry PowerPress Podcasting plugin before 6.0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cat parameter in a powerpress-editcategoryfeed action in the powerpressadmin_categoryfeeds.php page to wp-admin/admin.php.
- CVSS:
- 6.1
- Affected:
- up to 6.0.0
- Fixed in:
- 6.0.1
- Disclosed:
- Jan 29, 2015
CVE-2015-1385 on NVD →
PowerPress Podcasting plugin by Blubrry [powerpress] < 11.9.18
unknown
- Affected:
- up to 11.9.18
- Fixed in:
- 11.9.18
CVE-2024-9227 on NVD →
PowerPress Podcasting plugin by Blubrry [powerpress] < 11.9.18
unknown
- Affected:
- up to 11.9.18
- Fixed in:
- 11.9.18
CVE-2024-9230 on NVD →