PT-2026-67659 · WordPress · Powerpress Podcasting
CVE-2026-16293
·
Published
2026-08-04
·
Updated
2026-08-04
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PowerPress Podcasting versions prior to 11.16.11
Description
Insufficient sanitization and escaping of certain Podcast Episode settings allow users with Contributor roles or higher to execute Stored Cross-Site Scripting (XSS) attacks. This occurs even when the
unfiltered html capability is disabled. The issue specifically involves the Podcast Episode Chapters URL.Recommendations
Update PowerPress Podcasting to version 11.16.11 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Powerpress Podcasting