Stored Cross-Site Scripting Vulnerability in Blubrry PowerPress Plugin for WordPress
CVE-2026-2988
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 April 2026
What is CVE-2026-2988?
The Blubrry PowerPress plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability, which arises due to inadequate input sanitization and output escaping in the 'powerpress' and 'podcast' shortcodes. This flaw allows authenticated attackers, who have contributor-level access or higher, to inject arbitrary web scripts into pages. These scripts may execute whenever users visit the compromised page, leading to potential data theft, session hijacking, or other security risks.
Affected Version(s)
PowerPress Podcasting plugin by Blubrry 0 <= 11.15.15