← Back to search

CVE-2026-16293

6.8 MEDIUM

Published 2026-08-04 · Updated 2026-08-04

AI risk analysis

Summary
The flaw allows contributors to inject malicious scripts into podcast episode settings, leading to cross-site scripting attacks even when HTML filtering is disabled.
Exploitability
Exploitation requires a contributor-level user and access to the affected plugin settings; moderate effort needed.
Blast radius
If exploited, it could lead to data theft or manipulation of podcast content visible to all site visitors.
Prioritized remediation
Update PowerPress Podcasting to version 11.16.11 or later immediately.
xsswp-plugincontent-injectioncontributor

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Podcast Episode settings, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-79

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.