CVE-2026-16293: Unknown Powerpress Podcasting Plugin By Blubrry

Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Podcast Episode settings, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Affected products

  • Unknown Powerpress Podcasting Plugin By Blubrry: before 11.16.11 (fixed in 11.16.11)

Published 2026-08-04. Last modified 2026-08-26.