PowerPress Podcasting plugin by Blubrry
powerpress · plugin
Known security vulnerabilities for PowerPress Podcasting plugin by Blubrry. Find out in seconds which version runs on your site with WP Lens.
18 known vulnerabilities
1 critical · 1 exploitable without logging in · latest Jun 18, 2026
Listed on wordpress.org · latest 11.17.11 · last updated Oct 1, 2026 · 20K+ installs
wordpress.org status checked on Oct 2, 2026
Vulnerabilities
- Critical 9.9
CVE-2025-46264login required≤ 11.12.5
WordPress PowerPress Podcasting <= 11.12.5 - Arbitrary File Upload Vulnerability
- High 8.8
CVE-2026-23798login required≤ 11.15.10
WordPress PowerPress Podcasting plugin <= 11.15.10 - PHP Object Injection vulnerability
- High 8.8
CVE-2025-13536contributor+≤ 11.15.2
Blubrry PowerPress <= 11.15.2 - Authenticated (Contributor+) Arbitrary File Upload via 'powerpress_edit_post'
- High 8.5
CVE-2026-24637contributor+≤ 11.15.10
WordPress PowerPress Podcasting plugin <= 11.15.10 - SQL Injection vulnerability
- Medium 6.5
CVE-2025-32690login required≤ 11.12.5
WordPress PowerPress Podcasting plugin <= 11.12.5 - Cross Site Scripting (XSS) Vulnerability
- Medium 6.5
CVE-2023-41239login required≤ 11.0.6
WordPress PowerPress Podcasting Plugin <= 11.0.6 is vulnerable to Server Side Request Forgery (SSRF)
- Medium 6.4
CVE-2026-12098author+≤ 11.16.8
PowerPress Podcasting plugin by Blubrry <= 11.16.8 - Authenticated (Author+) Stored Cross-Site Scripting via 'embed' Episode Meta Field
- Medium 6.4
CVE-2026-2988contributor+≤ 11.15.15
Blubrry PowerPress <= 11.15.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via powerpress and podcast Shortcodes
- Medium 6.4
CVE-2024-9543contributor+≤ 11.9.18
Powerpress <= 11.9.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via skipto Shortcode
- Medium 6.4
CVE-2024-6588contributor+≤ 11.9.10
PowerPress Podcasting plugin by Blubrry <= 11.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via media_url Parameter
- Medium 5.9
CVE-2026-32351high privilege≤ 11.15.13
WordPress PowerPress Podcasting plugin <= 11.15.13 - Cross Site Scripting (XSS) vulnerability
- Medium 5.4
CVE-2015-9410login required
The Blubrry PowerPress Podcasting plugin 6.0.4 for WordPress has XSS via the tab parameter.
- Medium 5.4
CVE-2023-30778contributor+≤ 10.0.1
WordPress PowerPress Podcasting Plugin <= 10.0.1 is vulnerable to Cross Site Scripting (XSS)
- Medium 5.4
CVE-2023-1917contributor+≤ 10.0
PowerPress <= 10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
- Medium 4.9
CVE-2025-49984login required≤ 11.13.11
WordPress PowerPress Podcasting plugin <= 11.13.11 - Server Side Request Forgery (SSRF) Vulnerability
- Medium 4.9
CVE-2025-32691login required≤ 11.12.6
WordPress PowerPress Podcasting plugin <= 11.12.6 - Server Side Request Forgery (SSRF) Vulnerability
- Medium 4.3
CVE-2025-64201unauthenticated · needs a click≤ 11.13.12
WordPress PowerPress Podcasting plugin <= 11.13.12 - Cross Site Request Forgery (CSRF) vulnerability
- Medium 4.3
Cross-site scripting (XSS) vulnerability in the Blubrry PowerPress Podcasting plugin before 6.0.1 for WordPress allows remote attackers to i
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).