Stored XSS Vulnerability in Blubrry PowerPress Podcasting Plugin
CVE-2026-32351

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 March 2026

What is CVE-2026-32351?

The Blubrry PowerPress Podcasting plugin is susceptible to a stored cross-site scripting (XSS) vulnerability that could allow attackers to inject malicious scripts. This vulnerability affects users of versions up to and including 11.15.13. If exploited, it could allow attackers to execute arbitrary scripts in the context of authenticated users, leading to potential data theft or operational disruptions. Website administrators should ensure they are running the latest version and apply necessary security measures.

Affected Version(s)

PowerPress Podcasting 0 <= 11.15.13

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jitlada | Patchstack Bug Bounty Program
.