CVE-2026-16293
6.8 MEDIUMPublished 2026-08-04 · Updated 2026-08-04
AI risk analysis
- Summary
- The flaw allows contributors to inject malicious scripts into podcast episode settings, leading to cross-site scripting attacks even when HTML filtering is disabled.
- Exploitability
- Exploitation requires a contributor-level user and access to the affected plugin settings; moderate effort needed.
- Blast radius
- If exploited, it could lead to data theft or manipulation of podcast content visible to all site visitors.
- Prioritized remediation
- Update PowerPress Podcasting to version 11.16.11 or later immediately.
xsswp-plugincontent-injectioncontributor
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Podcast Episode settings, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-79
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.