Stored Cross-Site Scripting Vulnerability in PowerPress Podcasting Plugin by Blubrry
CVE-2026-16293
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 August 2026
Badges
What is CVE-2026-16293?
The PowerPress Podcasting plugin by Blubrry fails to properly sanitize and escape several settings related to Podcast Episodes. This oversight allows attackers with low-level roles, such as Contributor, to craft malicious scripts that can be stored and executed within the applications of unsuspecting users. This vulnerability highlights significant security weaknesses in user role permissions, demonstrating that even restricted users can exploit the plugin's inadequate protections, leading to potential unauthorized actions and data exposure.
Affected Version(s)
PowerPress Podcasting plugin by Blubrry 0 < 11.16.11
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.