{"id":"CVE-2026-16293","published":"2026-08-04T07:16:29.913","lastModified":"2026-08-04T15:16:26.767","description":"The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Podcast Episode settings, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.","cvssScore":6.8,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/04aa5ba8-2654-4e71-90af-83cfd92635f8/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows contributors to inject malicious scripts into podcast episode settings, leading to cross-site scripting attacks even when HTML filtering is disabled.","exploitability":"Exploitation requires a contributor-level user and access to the affected plugin settings; moderate effort needed.","blast_radius":"If exploited, it could lead to data theft or manipulation of podcast content visible to all site visitors.","remediation":"Update PowerPress Podcasting to version 11.16.11 or later immediately.","tags":["xss","wp-plugin","content-injection","contributor"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T07:04:20.829Z"}}