Impact
The PowerPress Podcasting plugin for WordPress is vulnerable to authenticated stored XSS via the 'embed' episode meta field. Classified as CWE‑79, it permits users with author-level or higher privileges to insert arbitrary JavaScript that is saved directly via update_post_meta(), bypassing WordPress’s kses filtering. Any user who views a page that renders the embed value will execute the injected script, enabling attackers to hijack sessions, deface content, or deliver malware.
Affected Systems
Blubrry PowerPress Podcasting plugin for WordPress, versions up to and including 11.16.8.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while the EPSS score of less than 1 % means the likelihood of exploitation is currently very low. The vulnerability is not listed in CISA’s KEV catalog. Attackers require authenticated access at author level or higher; once injected, the script runs for all viewers of the affected pages.
OpenCVE Enrichment