Impact
The vulnerability is a Cross‑Site Request Forgery flaw that enables an attacker to cause an authenticated user to unknowingly submit requests that the WordPress PowerPress Podcasting plugin would normally accept. This flaw undermines the integrity of actions performed by legitimate users, potentially allowing unauthorized operations within the plugin’s scope. The weakness is identified as CWE‑352.
Affected Systems
The Blubrry Podcasting PowerPress Podcasting plugin for WordPress is affected. All releases from the earliest known version through 11.17.9 are vulnerable, while version 11.17.11 and later include the fix.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. EPSS data is not available, suggesting limited public exploitation reports. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a malicious request sent to an authenticated user—such as via a deceptive link or embedded form—which triggers unintended plugin actions.
OpenCVE Enrichment