Vulnerabilities and security researches forpowerpress powerpress
Direction: ascendingJun 07, 2024
PowerPress Podcasting plugin by Blubrry # CVE-2023-30778
- CVE, Research URL
- Application
- Date
- Aug 15, 2023
- Research Description
- Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Blubrry PowerPress Podcasting plugin by Blubrry plugin <= 10.0.1 versions.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
PowerPress Podcasting plugin by Blubrry # CVE-2023-4820
- CVE, Research URL
- Application
- Date
- Oct 17, 2023
- Research Description
- The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.0.12 does not sanitize and escape the media url field in posts, which could allow users with privileges as low as contributor to inject arbitrary web scripts that could target a site admin or superadmin.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
PowerPress Podcasting plugin by Blubrry # CVE-2021-24123
- CVE, Research URL
- Application
- Date
- Mar 18, 2021
- Research Description
- Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.8, did not verify some of the uploaded feed images (such as the ones from Podcast Artwork section), allowing high privilege accounts (admin+) being able to upload arbitrary files, such as php, leading to RCE.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
PowerPress Podcasting plugin by Blubrry # CVE-2023-1917
- CVE, Research URL
- Application
- Date
- Jun 09, 2023
- Research Description
- The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: A partial fix for the issue was introduced in version 10.0.1, and an additional patch (version 10.0.2) was released to address a workaround.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
PowerPress Podcasting plugin by Blubrry # CVE-2023-41239
- CVE, Research URL
- Application
- Date
- Nov 13, 2023
- Research Description
- Server-Side Request Forgery (SSRF) vulnerability in Blubrry PowerPress Podcasting plugin by Blubrry.This issue affects PowerPress Podcasting plugin by Blubrry: from n/a through 11.0.6.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
PowerPress Podcasting plugin by Blubrry # CVE-2015-9410
- CVE, Research URL
- Application
- Date
- Sep 26, 2019
- Research Description
- The Blubrry PowerPress Podcasting plugin 6.0.4 for WordPress has XSS via the tab parameter.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
PowerPress Podcasting plugin by Blubrry # CVE-2015-1385
- CVE, Research URL
- Application
- Date
- Feb 02, 2015
- Research Description
- Cross-site scripting (XSS) vulnerability in the Blubrry PowerPress Podcasting plugin before 6.0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cat parameter in a powerpress-editcategoryfeed action in the powerpressadmin_categoryfeeds.php page to wp-admin/admin.php.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jun 30, 2024
PowerPress Podcasting plugin by Blubrry # CVE-2024-6297
- CVE, Research URL
- Application
- Date
- Jun 25, 2024
- Research Description
- Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that data back to a server. Currently, not all plugins have been patched and we strongly recommend uninstalling the plugins for the time being and running a complete malware scan.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jul 13, 2024
PowerPress Podcasting plugin by Blubrry # CVE-2024-6588
- CVE, Research URL
- Application
- Date
- Jul 12, 2024
- Research Description
- The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘media_url’ parameter in all versions up to, and including, 11.9.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Oct 12, 2024
PowerPress Podcasting plugin by Blubrry # CVE-2024-9543
- CVE, Research URL
- Application
- Date
- Oct 11, 2024
- Research Description
- The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skipto' shortcode in all versions up to, and including, 11.9.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Apr 10, 2025
PowerPress Podcasting plugin by Blubrry # CVE-2025-32690
- CVE, Research URL
- Application
- Date
- Apr 09, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Angelo Mandato PowerPress Podcasting allows DOM-Based XSS. This issue affects PowerPress Podcasting: from n/a through 11.12.4.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
PowerPress Podcasting plugin by Blubrry # CVE-2025-32691
- CVE, Research URL
- Application
- Date
- Apr 09, 2025
- Research Description
- Server-Side Request Forgery (SSRF) vulnerability in Angelo Mandato PowerPress Podcasting allows Server Side Request Forgery. This issue affects PowerPress Podcasting: from n/a through 11.12.4.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable