Impact
The vulnerability is a missing authorization flaw that allows an attacker to retrieve embedded sensitive data from the PowerPress Podcasting plugin. This flaw is identified as CWE-862, resulting in a potential confidentiality breach. An unauthenticated or non‑privileged user can access data that should be restricted, exposing personal or private information stored within the WordPress site.
Affected Systems
The affected product is the Blubrry Podcasting PowerPress Podcasting plugin for WordPress. Versions up to and including 11.17.9 are impacted; all later releases are assumed to have been patched.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, and the absence of an EPSS score means current exploitation probability is unknown. The plugin’s function to retrieve embedded data is typically exposed over HTTP, so the likely attack vector is a remote web request without authentication. Because the flaw resides in a widely used WordPress plugin, the risk is notable for sites that have not applied the recommended patch and may expose sensitive content to unauthenticated users.
OpenCVE Enrichment