Blubrry · Powerpress Podcasting · CVE-2026-12098
**Name of the Vulnerable Software and Affected Versions**
PowerPress Podcasting plugin by Blubrry versions prior to 11.16.9
**Description**
The PowerPress Podcasting plugin for WordPress contains a Stored Cross-Site Scripting issue due to insufficient input sanitization and output escaping. Authenticated attackers with author-level access or higher can inject arbitrary web scripts into pages. This occurs because the `embed` Episode Meta Field is stored using the `update post meta()` function instead of the WordPress core post content pipeline, bypassing the kses-on-save filtering and standard role-based mitigations for users who lack the `unfiltered html` capability.
**Recommendations**
Update to a version later than 11.16.8.