Cross-Site Request Forgery Vulnerability in Blubrry PowerPress Podcasting Plugin
CVE-2025-64201

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
29 October 2025

What is CVE-2025-64201?

The Blubrry PowerPress Podcasting plugin contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to execute unauthorized actions on behalf of an authenticated user. This exposure potentially compromises the integrity of user data and application workflows. Users are advised to update to a patched version to mitigate the risks associated with this vulnerability.

Affected Version(s)

PowerPress Podcasting <= n/a

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo | Patchstack Bug Bounty Program
.