Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-104387 2 Blubrry, Wordpress-extensions 2 Powerpress Podcasting, Powerpress Podcasting 2026-10-06 7.2 High
Unauthenticated Broken Access Control in PowerPress Podcasting <= 11.17.9 versions.
CVE-2026-97319 1 Wordpress-extensions 1 Powerpress 2026-09-28 6.8 Medium
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribute before outputting it in a page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.