Sceawere

Vulnerability Detail

CVE-2026-104388UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

PowerPress Unauthorized Data Retrieval Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
10h ago
Vendor
Blubrry Podcasting
Product
PowerPress Podcasting
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Missing Authorization vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Retrieve Embedded Sensitive Data.This issue affects PowerPress Podcasting: from n/a through 11.17.9.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-05T09:17:07.520Z",
  "pubdate": "2026-10-05T09:17:07.520Z",
  "executiveSummary": "A Missing Authorization vulnerability exists in the Blubrry PowerPress Podcasting plugin, impacting versions up to and including 11.17.9.\nThe vulnerability allows unauthenticated or unauthorized actors to perform unauthorized retrieval of sensitive data embedded within the plugin's infrastructure.\nThis flaw resides in the plugin's access control mechanisms, which fail to properly validate user permissions before executing data retrieval operations.\nThe impact is significant, as it may lead to the exposure of proprietary information or sensitive configuration details managed by the podcasting suite.\nExploitation does not necessarily require high-level administrative privileges, potentially allowing remote attackers to scrape sensitive data via crafted requests.\nOrganizations using affected versions are at risk of data leakage, which could lead to further security compromises or unauthorized intelligence gathering by malicious entities.",
  "technicalDetails": "The core of the vulnerability is a Missing Authorization flaw within the PowerPress Podcasting plugin for WordPress. The plugin fails to perform adequate access control checks (e.g., capability validation via current_user_can() or nonces) on specific endpoints or functions responsible for returning embedded data to the client.\nWhen a user or automated agent triggers these specific functions, the backend processing logic does not verify if the requesting entity possesses the required privileges to view the requested resource. Consequently, the application processes the request and returns sensitive data that should be restricted to authenticated administrators or authorized users.\nThe attack flow typically involves an attacker identifying the endpoint responsible for fetching embedded podcasting data or configuration properties. By crafting a specific HTTP request targeting these vulnerable functions, an attacker can bypass the intended authorization logic. The application, failing to enforce a 'deny by default' security posture, serves the requested sensitive data directly in the HTTP response body.\nThis vulnerability is particularly dangerous as it allows for unauthorized data exfiltration without requiring an active session or elevated privileges in many scenarios. The exposure surface includes any information deemed 'embedded' or handled by the plugin's retrieval functions, which could range from API keys, feed configurations, or other internal metadata handled by the PowerPress framework.\nThe lack of proper session management or authorization token validation allows these requests to be executed repeatedly, potentially enabling mass data harvesting. Because the plugin does not gate these specific functions, any external request targeting the known path is honored by the server, leading to an information disclosure scenario that persists throughout versions 11.17.9 and prior.\nSuccessful exploitation requires the attacker to have network reachability to the web server hosting the PowerPress plugin. No complex payloads are required to trigger the vulnerability; a simple GET or POST request targeting the exposed function is sufficient to retrieve the target data. The post-exploitation impact is limited to the confidentiality of the data exposed via the plugin, but this can serve as a pivot point for further attacks on the WordPress installation if sensitive credentials are leaked."
}
CVE-2026-104388: PowerPress Unauthorized Data Retrieval Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere