Blubrry PowerPress <= 11.15.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via powerpress and podcast Shortcodes
PowerPress Podcasting plugin by Blubrry
Minimum safe version
11.15.16
Update to 11.15.16 or later to address 28 fixable vulnerabilities
CVE-2026-32351
CVE-2026-23798
CVE-2025-13536
CVE-2025-64201
CVE-2025-49984
PowerPress Podcasting <= 11.9.17 - Authenticated (Author+) Stored Cross-Site Scripting
CVE-2025-46264
PowerPress Podcasting <= 11.9.17 - Authenticated (Author+) Stored Cross-Site Scripting
CVE-2025-32690
CVE-2025-32691
CVE-2024-9543
CVE-2024-6588
WordPress PowerPress Podcasting Plugin 11.9.3–11.9.4 is vulnerable to Backdoor
WordPress PowerPress Podcasting Plugin < 11.0.12 is vulnerable to Cross Site Scripting (XSS)
WordPress PowerPress Podcasting Plugin < 11.0.11 is vulnerable to Cross Site Scripting (XSS)
PowerPress <= 11.0.11 - Authenticated(Contributor+) Stored Cross-Site Scripting via Media URL
CVE-2023-41239
PowerPress <= 10.2.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Feed[title]'
WordPress PowerPress Podcasting Plugin <= 10.2.3 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-30778
CVE-2023-1917
WordPress Blubrry PowerPress Podcasting Plugin <= 6.0.4 - XSS
WordPress PowerPress Podcasting plugin <= 8.3.7 - Authenticated Arbitrary File Upload leading to Remote Code Execution (RCE) vulnerability
WordPress PowerPress Podcasting plugin <= 8.6.1 - Multiple Authenticated Cross-Site Scripting (XSS) vulnerabilities
CVE-2015-1385
CVE-2015-9410
CVE-2021-24123