PowerPress Podcasting plugin by Blubrry

Information

Software Type Plugin
Software Slug powerpress (view on wordpress.org)
Software Status Active
Software Author blubrry
Software Website blubrry.com
Software Downloads 6,277,347
Software Active Installs 20,000
Software Record Last Updated July 10, 2026

Showing 1-20 of 24 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
PowerPress Podcasting plugin by Blubrry <= 11.16.8 - Authenticated (Author+) Stored Cross-Site Scripting via 'embed' Episode Meta Field Patched CVE-2026-12098 6.4 Mukhlis Amien June 17, 2026
PowerPress Podcasting plugin by Blubrry <= 11.15.10 - Authenticated (Contributor+) SQL Injection Patched CVE-2026-24637 6.5 Phat RiO May 20, 2026
Blubrry PowerPress <= 11.15.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via powerpress and podcast Shortcodes Patched CVE-2026-2988 6.4 Muhammad Yudha - DJ April 7, 2026
PowerPress Podcasting plugin by Blubrry <= 11.15.10 - Authenticated (Contributor+) PHP Object Injection Patched CVE-2026-23798 7.5 Muhammad Yudha - DJ February 25, 2026
PowerPress Podcasting <= 11.15.13 - Authenticated (Author+) Stored Cross-Site Scripting Patched CVE-2026-32351 6.4 Athiwat Tiprasaharn (Jitlada) February 13, 2026
Blubrry PowerPress <= 11.15.2 - Authenticated (Contributor+) Arbitrary File Upload via 'powerpress_edit_post' Patched CVE-2025-13536 8.8 ISMAILSHADOW November 26, 2025
PowerPress Podcasting <= 11.13.12 - Cross-Site Request Forgery Patched CVE-2025-64201 4.3 daroo October 21, 2025
PowerPress Podcasting <= 11.13.11 - Authenticated (Contributor+) Server-Side Request Forgery Patched CVE-2025-49984 6.4 Nguyễn Trung Kiên June 19, 2025
PowerPress Podcasting plugin by Blubrry <= 11.12.5 - Authenticated (Contributor+) Stored Cross-Site Scripting Patched CVE-2025-46264 8.8 Trương Hữu Phúc (truonghuuphuc) April 23, 2025
PowerPress Podcasting <= 11.12.6 - Authenticated (Contributor+) Server-Side Request Forgery Patched CVE-2025-32691 5.4 Trương Hữu Phúc (truonghuuphuc) April 9, 2025
PowerPress Podcasting <= 11.12.5 - Authenticated (Contributor+) Stored Cross-Site Scripting Patched CVE-2025-32690 6.4 Trương Hữu Phúc (truonghuuphuc) April 9, 2025
PowerPress Podcasting <= 11.9.17 - Authenticated (Author+) Stored Cross-Site Scripting Patched CVE-2024-9230 6.4 Bob Matyas March 24, 2025
PowerPress Podcasting <= 11.9.17 - Authenticated (Author+) Stored Cross-Site Scripting Patched CVE-2024-9227 6.4 Krugov Artyom March 2, 2025
Powerpress <= 11.9.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via skipto Shortcode Patched CVE-2024-9543 6.4 Jack Taylor October 10, 2024
PowerPress Podcasting plugin by Blubrry <= 11.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via media_url Parameter Patched CVE-2024-6588 6.4 Webbernaut July 11, 2024
Several WordPress.org Plugins <= Various Versions - Injected Backdoor Patched CVE-2024-6297 10.0 June 24, 2024
PowerPress <= 11.0.11 - Authenticated(Contributor+) Stored Cross-Site Scripting via Media URL Patched CVE-2023-4820 6.4 emad September 13, 2023
PowerPress <= 11.0.6 - Authenticated (Contributor+) Server-Side Request Forgery via wp_ajax_powerpress_media_info Patched CVE-2023-41239 5.4 Kévin Mosbahi (Mika) August 29, 2023
PowerPress <= 10.2.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Feed[title]' Patched 4.4 June 6, 2023
PowerPress <= 10.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Patched CVE-2023-30778 5.4 Kévin Mosbahi (Mika) April 17, 2023

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation