Description
Cross-Site Request Forgery (CSRF) vulnerability in blubrry PowerPress Podcasting powerpress allows Cross Site Request Forgery.This issue affects PowerPress Podcasting: from n/a through <= 11.13.12.
Published: 2025-10-29
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability permits an attacker to issue state‑changing requests on behalf of an authenticated user without the user's knowledge. A malicious page could submit forms or API calls to the PowerPress Podcasting plugin, potentially creating, modifying, or deleting podcast entries. This weakness is classified as CWE‑352 and does not grant direct code execution but results in integrity and possibly availability impacts if the attacker overwhelms the system or performs privileged actions.

Affected Systems

WordPress sites running the PowerPress Podcasting plugin from older versions up to and including 11.13.12 are affected. The product is provided by blubrry and is used by WordPress users to manage podcast content. Any installation of the plugin within the specified version range is vulnerable. The exact version breakdown is not provided beyond the upper bound of 11.13.12.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity while the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability has not been listed in CISA’s KEV catalog. Exploitation would typically involve tricking an authenticated user into visiting a crafted page that triggers a request to the vulnerable plugin endpoints. The attack can succeed if the victim's session cookie is present, and the plugin does not perform proper CSRF token validation.

Generated by OpenCVE AI on April 29, 2026 at 23:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the PowerPress Podcasting plugin to the latest stable release (any version above 11.13.12).
  • Reconfigure the plugin to restrict state‑changing operations to users with appropriate capabilities and disable any unused management features.
  • Deploy or enable a WordPress security plugin that enforces nonce verification on all front‑end forms and limits REST API access to authenticated users only.

Generated by OpenCVE AI on April 29, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 30 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Blubrry
Blubrry powerpress Podcasting
Wordpress
Wordpress wordpress
Vendors & Products Blubrry
Blubrry powerpress Podcasting
Wordpress
Wordpress wordpress

Wed, 29 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Oct 2025 09:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in blubrry PowerPress Podcasting powerpress allows Cross Site Request Forgery.This issue affects PowerPress Podcasting: from n/a through <= 11.13.12.
Title WordPress PowerPress Podcasting plugin <= 11.13.12 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References

Subscriptions

Blubrry Powerpress Podcasting
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:10.739Z

Reserved: 2025-10-29T03:07:04.007Z

Link: CVE-2025-64201

cve-icon Vulnrichment

Updated: 2025-10-29T14:47:39.506Z

cve-icon NVD

Status : Deferred

Published: 2025-10-29T09:15:40.150

Modified: 2026-04-27T16:16:34.740

Link: CVE-2025-64201

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T23:30:22Z

Weaknesses