cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forpowerpress powerpress

Direction: descending
Apr 10, 2025

PowerPress Podcasting plugin by Blubrry # CVE-2025-32690

CVE, Research URL

CVE-2025-32690

Date
Apr 09, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Angelo Mandato PowerPress Podcasting allows DOM-Based XSS. This issue affects PowerPress Podcasting: from n/a through 11.12.4.
Affected versions
Min -, max -.
Status
vulnerable

PowerPress Podcasting plugin by Blubrry # CVE-2025-32691

CVE, Research URL

CVE-2025-32691

Date
Apr 09, 2025
Research Description
Server-Side Request Forgery (SSRF) vulnerability in Angelo Mandato PowerPress Podcasting allows Server Side Request Forgery. This issue affects PowerPress Podcasting: from n/a through 11.12.4.
Affected versions
Min -, max -.
Status
vulnerable
Oct 12, 2024

PowerPress Podcasting plugin by Blubrry # CVE-2024-9543

CVE, Research URL

CVE-2024-9543

Date
Oct 11, 2024
Research Description
The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skipto' shortcode in all versions up to, and including, 11.9.18 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable
Jul 13, 2024

PowerPress Podcasting plugin by Blubrry # CVE-2024-6588

CVE, Research URL

CVE-2024-6588

Date
Jul 12, 2024
Research Description
The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘media_url’ parameter in all versions up to, and including, 11.9.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable
Jun 30, 2024

PowerPress Podcasting plugin by Blubrry # CVE-2024-6297

CVE, Research URL

CVE-2024-6297

Date
Jun 25, 2024
Research Description
Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to create new, malicious, administrator users and send that data back to a server. Currently, not all plugins have been patched and we strongly recommend uninstalling the plugins for the time being and running a complete malware scan.
Affected versions
Min -, max -.
Status
vulnerable
Jun 07, 2024

PowerPress Podcasting plugin by Blubrry # CVE-2023-30778

CVE, Research URL

CVE-2023-30778

Date
Aug 15, 2023
Research Description
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Blubrry PowerPress Podcasting plugin by Blubrry plugin <= 10.0.1 versions.
Affected versions
Min -, max -.
Status
vulnerable

PowerPress Podcasting plugin by Blubrry # CVE-2023-4820

CVE, Research URL

CVE-2023-4820

Date
Oct 17, 2023
Research Description
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.0.12 does not sanitize and escape the media url field in posts, which could allow users with privileges as low as contributor to inject arbitrary web scripts that could target a site admin or superadmin.
Affected versions
Min -, max -.
Status
vulnerable

PowerPress Podcasting plugin by Blubrry # CVE-2021-24123

CVE, Research URL

CVE-2021-24123

Date
Mar 18, 2021
Research Description
Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.8, did not verify some of the uploaded feed images (such as the ones from Podcast Artwork section), allowing high privilege accounts (admin+) being able to upload arbitrary files, such as php, leading to RCE.
Affected versions
Min -, max -.
Status
vulnerable

PowerPress Podcasting plugin by Blubrry # CVE-2023-1917

CVE, Research URL

CVE-2023-1917

Date
Jun 09, 2023
Research Description
The PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: A partial fix for the issue was introduced in version 10.0.1, and an additional patch (version 10.0.2) was released to address a workaround.
Affected versions
Min -, max -.
Status
vulnerable

PowerPress Podcasting plugin by Blubrry # CVE-2023-41239

CVE, Research URL

CVE-2023-41239

Date
Nov 13, 2023
Research Description
Server-Side Request Forgery (SSRF) vulnerability in Blubrry PowerPress Podcasting plugin by Blubrry.This issue affects PowerPress Podcasting plugin by Blubrry: from n/a through 11.0.6.
Affected versions
Min -, max -.
Status
vulnerable

PowerPress Podcasting plugin by Blubrry # CVE-2015-9410

CVE, Research URL

CVE-2015-9410

Date
Sep 26, 2019
Research Description
The Blubrry PowerPress Podcasting plugin 6.0.4 for WordPress has XSS via the tab parameter.
Affected versions
Min -, max -.
Status
vulnerable

PowerPress Podcasting plugin by Blubrry # CVE-2015-1385

CVE, Research URL

CVE-2015-1385

Date
Feb 02, 2015
Research Description
Cross-site scripting (XSS) vulnerability in the Blubrry PowerPress Podcasting plugin before 6.0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cat parameter in a powerpress-editcategoryfeed action in the powerpressadmin_categoryfeeds.php page to wp-admin/admin.php.
Affected versions
Min -, max -.
Status
vulnerable