Stored Cross-Site Scripting Vulnerability in Blubrry PowerPress Plugin for WordPress
CVE-2026-2988

6.4MEDIUM

What is CVE-2026-2988?

The Blubrry PowerPress plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability, which arises due to inadequate input sanitization and output escaping in the 'powerpress' and 'podcast' shortcodes. This flaw allows authenticated attackers, who have contributor-level access or higher, to inject arbitrary web scripts into pages. These scripts may execute whenever users visit the compromised page, leading to potential data theft, session hijacking, or other security risks.

Affected Version(s)

PowerPress Podcasting plugin by Blubrry 0 <= 11.15.15

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Yudha - DJ
.