PT-2026-67659 · WordPress · Powerpress Podcasting

CVE-2026-16293

·

Published

2026-08-04

·

Updated

2026-08-04

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PowerPress Podcasting versions prior to 11.16.11
Description Insufficient sanitization and escaping of certain Podcast Episode settings allow users with Contributor roles or higher to execute Stored Cross-Site Scripting (XSS) attacks. This occurs even when the unfiltered html capability is disabled. The issue specifically involves the Podcast Episode Chapters URL.
Recommendations Update PowerPress Podcasting to version 11.16.11 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16293

Affected Products

Powerpress Podcasting