Impact
The flaw in PowerPress Podcasting plugin before version 11.17.2 allows a user with contributor or higher privileges to inject arbitrary JavaScript into a custom block attribute that is rendered without sanitization. This results in a stored cross‑site scripting vulnerability that can compromise any visitor who loads a page containing the offending block. Potential consequences include session hijacking, cookie theft, defacement, or execution of further malicious payloads on the client side.
Affected Systems
Any WordPress site running the PowerPress Podcasting plugin older than 11.17.2 is affected. The problem arises in the plugin’s Podcast Player block, so sites that use that block for audio or video playback are at risk. The effect is limited to users with contributor or higher roles who can edit the block; normal site visitors are the attack targets.
Risk and Exploitability
The CVSS score is not publicly listed, and no EPSS value is provided, but the CAP of the vulnerability suggests high potential impact. An attacker needs only contributor‑level access to inject the malicious payload; once stored, it executes automatically for all visitors, giving the attacker a broad attack surface. No current exploit evidence or KEV listing indicates the flaw is not yet actively exploited, but the lack of a sanitization fix presents a significant security risk.
OpenCVE Enrichment