Extension WordPress

Vulnérabilités PowerPress Podcasting plugin by Blubrry

Cette page rassemble les failles publiées pour PowerPress Podcasting plugin by Blubrry, leurs plages de versions affectées et les correctifs signalés dans la base locale.

24Vulnérabilités
0Critiques
24Avec correctif
10,0CVSS maximal

Historique de sécurité

CVE et vulnérabilités de PowerPress Podcasting plugin by Blubrry

24 fiches

CVE-2026-12098 Moyenne · 6,4
PowerPress Podcasting plugin by Blubrry

PowerPress Podcasting plugin by Blubrry <= 11.16.8 – Authenticated (Author+) Stored Cross-Site Scripting via 'embed' Episode Meta Field

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed' Episode Meta Field in all versions up to, and including, 11.16.8 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-11.16.8

Correctif

11.16.9

Publication

17/06/2026

CVE-2026-24637 Moyenne · 6,5
PowerPress Podcasting plugin by Blubrry

PowerPress Podcasting plugin by Blubrry <= 11.15.10 – Authenticated (Contributor+) SQL Injection

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 11.15.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…

Versions affectées

*-11.15.10

Correctif

11.15.11

Publication

20/05/2026

CVE-2026-2988 Moyenne · 6,4
PowerPress Podcasting plugin by Blubrry

Blubrry PowerPress <= 11.15.15 – Authenticated (Contributor+) Stored Cross-Site Scripting via powerpress and podcast Shortcodes

The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'powerpress' and 'podcast' shortcodes in versions up to, and including, 11.15.15 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-11.15.15

Correctif

11.15.16

Publication

07/04/2026

CVE-2026-23798 Élevée · 7,5
PowerPress Podcasting plugin by Blubrry

PowerPress Podcasting plugin by Blubrry <= 11.15.10 – Authenticated (Contributor+) PHP Object Injection

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 11.15.10 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access…

Versions affectées

*-11.15.10

Correctif

11.15.11

Publication

25/02/2026

CVE-2026-32351 Moyenne · 6,4
PowerPress Podcasting plugin by Blubrry

PowerPress Podcasting <= 11.15.13 – Authenticated (Author+) Stored Cross-Site Scripting

The PowerPress Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 11.15.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and…

Versions affectées

*-11.15.13

Correctif

11.15.14

Publication

13/02/2026

CVE-2025-13536 Élevée · 8,8
PowerPress Podcasting plugin by Blubrry

Blubrry PowerPress <= 11.15.2 – Authenticated (Contributor+) Arbitrary File Upload via 'powerpress_edit_post'

The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 11.15.2. This is due to the plugin validating file extensions but not halting…

Versions affectées

*-11.15.2

Correctif

11.15.3

Publication

26/11/2025

CVE-2025-64201 Moyenne · 4,3
PowerPress Podcasting plugin by Blubrry

PowerPress Podcasting <= 11.13.12 – Cross-Site Request Forgery

The PowerPress Podcasting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 11.13.12. This is due to missing or incorrect nonce validation on the 'powerpress-sync-progad' action. This makes it possible for unauthenticated…

Versions affectées

*-11.13.12

Correctif

11.14

Publication

21/10/2025

CVE-2025-49984 Moyenne · 6,4
PowerPress Podcasting plugin by Blubrry

PowerPress Podcasting <= 11.13.11 – Authenticated (Contributor+) Server-Side Request Forgery

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 11.13.11. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web…

Versions affectées

*-11.13.11

Correctif

11.13.12

Publication

19/06/2025

CVE-2025-46264 Élevée · 8,8
PowerPress Podcasting plugin by Blubrry

PowerPress Podcasting plugin by Blubrry <= 11.12.5 – Authenticated (Contributor+) Stored Cross-Site Scripting

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 11.12.5. This makes it possible for authenticated attackers, with Contributor-level…

Versions affectées

*-11.12.5

Correctif

11.12.6

Publication

23/04/2025

CVE-2025-32690 Moyenne · 6,4
PowerPress Podcasting plugin by Blubrry

PowerPress Podcasting <= 11.12.5 – Authenticated (Contributor+) Stored Cross-Site Scripting

The PowerPress Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 11.12.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…

Versions affectées

*-11.12.5

Correctif

11.12.6

Publication

09/04/2025

CVE-2025-32691 Moyenne · 5,4
PowerPress Podcasting plugin by Blubrry

PowerPress Podcasting <= 11.12.6 – Authenticated (Contributor+) Server-Side Request Forgery

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 11.12.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web…

Versions affectées

*-11.12.6

Correctif

11.12.7

Publication

09/04/2025

CVE-2024-9230 Moyenne · 6,4
PowerPress Podcasting plugin by Blubrry

PowerPress Podcasting <= 11.9.17 – Authenticated (Author+) Stored Cross-Site Scripting

The PowerPress Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Podcast URLs in versions up to, and including, 11.9.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-11.9.17

Correctif

11.9.18

Publication

24/03/2025

CVE-2024-9227 Moyenne · 6,4
PowerPress Podcasting plugin by Blubrry

PowerPress Podcasting <= 11.9.17 – Authenticated (Author+) Stored Cross-Site Scripting

The PowerPress Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Podcast URLs in versions up to, and including, 11.9.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-11.9.17

Correctif

11.9.18

Publication

02/03/2025

CVE-2024-9543 Moyenne · 6,4
PowerPress Podcasting plugin by Blubrry

Powerpress <= 11.9.18 – Authenticated (Contributor+) Stored Cross-Site Scripting via skipto Shortcode

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skipto' shortcode in all versions up to, and including, 11.9.18 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-11.9.18

Correctif

11.9.19

Publication

10/10/2024

CVE-2024-6588 Moyenne · 6,4
PowerPress Podcasting plugin by Blubrry

PowerPress Podcasting plugin by Blubrry <= 11.9.10 – Authenticated (Contributor+) Stored Cross-Site Scripting via media_url Parameter

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘media_url’ parameter in all versions up to, and including, 11.9.10 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-11.9.10

Correctif

11.9.11

Publication

11/07/2024

CVE-2024-6297 Informationnelle
PowerPress Podcasting plugin by Blubrry

Several WordPress.org Plugins <= Various Versions – Injected Backdoor

Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to…

Versions affectées

11.9.3-11.9.4

Correctif

11.9.6

Publication

24/06/2024

CVE-2023-4820 Moyenne · 6,4
PowerPress Podcasting plugin by Blubrry

PowerPress <= 11.0.11 – Authenticated(Contributor+) Stored Cross-Site Scripting via Media URL

The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the media URL in versions up to, and including, 11.0.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…

Versions affectées

[*, 11.0.12)

Correctif

11.0.12

Publication

13/09/2023

CVE-2023-41239 Moyenne · 5,4
PowerPress Podcasting plugin by Blubrry

PowerPress <= 11.0.6 – Authenticated (Contributor+) Server-Side Request Forgery via wp_ajax_powerpress_media_info

The PowerPress plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 11.0.6 via the wp_ajax_powerpress_media_info AJAX action. This can allow authenticated attackers, with contributor-level permission and above, to make web requests to…

Versions affectées

*-11.0.6

Correctif

11.0.7

Publication

29/08/2023

Vulnérabilité Moyenne · 4,4
PowerPress Podcasting plugin by Blubrry

PowerPress <= 10.2.3 – Authenticated (Administrator+) Stored Cross-Site Scripting via 'Feed[title]'

The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Feed[title]’ parameter in versions up to, and including, 10.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-10.2.3

Correctif

10.2.4

Publication

06/06/2023

CVE-2023-30778 Moyenne · 5,4
PowerPress Podcasting plugin by Blubrry

PowerPress <= 10.0.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 10.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…

Versions affectées

*-10.0.1

Correctif

10.0.2

Publication

17/04/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités