Description
Cross-Site Request Forgery (CSRF) vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Cross Site Request Forgery.This issue affects PowerPress Podcasting: from n/a through 11.17.9.
Published: 2026-10-05
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Request Forgery
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery flaw that enables an attacker to cause an authenticated user to unknowingly submit requests that the WordPress PowerPress Podcasting plugin would normally accept. This flaw undermines the integrity of actions performed by legitimate users, potentially allowing unauthorized operations within the plugin’s scope. The weakness is identified as CWE‑352.

Affected Systems

The Blubrry Podcasting PowerPress Podcasting plugin for WordPress is affected. All releases from the earliest known version through 11.17.9 are vulnerable, while version 11.17.11 and later include the fix.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity. EPSS data is not available, suggesting limited public exploitation reports. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a malicious request sent to an authenticated user—such as via a deceptive link or embedded form—which triggers unintended plugin actions.

Generated by OpenCVE AI on October 5, 2026 at 13:35 UTC.

Remediation

Vendor Solution

Update the WordPress PowerPress Podcasting plugin to the latest available version (at least 11.17.11).


OpenCVE Recommended Actions

  • Update the PowerPress Podcasting plugin to version 11.17.11 or newer, which contains the CSRF mitigation.
  • Restrict the use of high‑privilege WordPress accounts by reviewing and limiting administrative roles, ensuring only essential users have elevated permissions.
  • Implement general WordPress security best practices, including keeping core, themes, and other plugins up to date and enabling existing CSRF token checks on forms where possible.

Generated by OpenCVE AI on October 5, 2026 at 13:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Cross Site Request Forgery.This issue affects PowerPress Podcasting: from n/a through 11.17.9.
Title WordPress PowerPress Podcasting plugin <= 11.17.9 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-05T08:38:36.801Z

Reserved: 2026-10-02T00:22:13.106Z

Link: CVE-2026-104407

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:08.487

Modified: 2026-10-05T09:17:08.487

Link: CVE-2026-104407

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T13:45:07Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)