CSRF Vulnerability in Blubrry Podcasting PowerPress Plugin
CVE-2026-104407

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 October 2026

What is CVE-2026-104407?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Blubrry Podcasting PowerPress plugin, affecting all versions from n/a through 11.17.9. This security flaw allows malicious actors to perform unauthorized actions on behalf of authenticated users, potentially leading to significant security breaches. Website administrators using this plugin should take immediate action to mitigate the risks associated with this vulnerability, including applying available updates, implementing security best practices, and monitoring for suspicious activity.

Affected Version(s)

PowerPress Podcasting 0 <= 11.17.9

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Intrudify | Patchstack Bug Bounty Program
.