Description
Missing Authorization vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Retrieve Embedded Sensitive Data.This issue affects PowerPress Podcasting: from n/a through 11.17.9.
Published: 2026-10-05
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a missing authorization flaw that allows an attacker to retrieve embedded sensitive data from the PowerPress Podcasting plugin. This flaw is identified as CWE-862, resulting in a potential confidentiality breach. An unauthenticated or non‑privileged user can access data that should be restricted, exposing personal or private information stored within the WordPress site.

Affected Systems

The affected product is the Blubrry Podcasting PowerPress Podcasting plugin for WordPress. Versions up to and including 11.17.9 are impacted; all later releases are assumed to have been patched.

Risk and Exploitability

The CVSS score of 5.3 indicates medium severity, and the absence of an EPSS score means current exploitation probability is unknown. The plugin’s function to retrieve embedded data is typically exposed over HTTP, so the likely attack vector is a remote web request without authentication. Because the flaw resides in a widely used WordPress plugin, the risk is notable for sites that have not applied the recommended patch and may expose sensitive content to unauthenticated users.

Generated by OpenCVE AI on October 5, 2026 at 10:23 UTC.

Remediation

Vendor Solution

Update the WordPress PowerPress Podcasting plugin to the latest available version (at least 11.17.11).


OpenCVE Recommended Actions

  • Update the WordPress PowerPress Podcasting plugin to version 11.17.11 or newer.
  • If an update is temporarily unavailable, restrict access to the "Retrieve Embedded Sensitive Data" feature or block the endpoint with server‑side rules so that only authorized users can invoke it.
  • Review the WordPress installation for any exposed sensitive data and secure or remove such data, ensuring proper authorization checks are enforced throughout the site.

Generated by OpenCVE AI on October 5, 2026 at 10:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 09:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Retrieve Embedded Sensitive Data.This issue affects PowerPress Podcasting: from n/a through 11.17.9.
Title WordPress PowerPress Podcasting plugin <= 11.17.9 - Sensitive Data Exposure vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-05T12:12:48.342Z

Reserved: 2026-10-02T00:22:13.105Z

Link: CVE-2026-104388

cve-icon Vulnrichment

Updated: 2026-10-05T12:12:44.199Z

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:07.520

Modified: 2026-10-05T13:16:51.120

Link: CVE-2026-104388

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T10:30:18Z

Weaknesses