Impact
The PowerPress Podcasting plugin for WordPress allows a user with the Contributor role to edit episode settings. Due to a lack of proper sanitisation and escaping, input in the Podcast Episode chapters URL can contain malicious scripts. When stored, these scripts will execute in the browsers of other site visitors, enabling an attacker to steal session cookies, perform account takeover, deface the site, or trick users into interacting with malicious external resources. This vulnerability is an example of improper neutralisation of input that can compromise confidentiality, integrity, and availability of the affected site.
Affected Systems
Vendors: Blubrry; Product: PowerPress Podcasting plugin for WordPress. Any installation running a version earlier than 11.16.11 is vulnerable. The flaw is exploitable by users who hold a Contributor account or any role with permission to edit podcast episodes, even when the unfiltered_html capability is disabled.
Risk and Exploitability
The Exploit Prediction Scoring System data is not available, and the vulnerability has not been listed in the CISA KEV catalogue. Nevertheless, stored XSS is widely regarded as high‑risk, and the low privileged attacker can directly inject code without needing to compromise the site’s authentication mechanisms. Because the flaw permits persistence in the database, the threat remains active until the affected plugin is updated. Given the breadth of potential impact and the relative ease of exploitation, the risk can be considered high.
OpenCVE Enrichment