Sceawere
Vulnerability Detail
CVE-2026-104407UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
CSRF Vulnerability in PowerPress Podcasting
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 10h ago
- Vendor
- Blubrry Podcasting
- Product
- PowerPress Podcasting
- Attack Type
- Cross-Site Request Forgery (CSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Cross-Site Request Forgery (CSRF) vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Cross Site Request Forgery.This issue affects PowerPress Podcasting: from n/a through 11.17.9.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-05T09:17:08.487Z",
"pubdate": "2026-10-05T09:17:08.487Z",
"executiveSummary": "The Blubrry Podcasting PowerPress Podcasting plugin is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability affecting versions from n/a through 11.17.9.\nA CSRF vulnerability occurs when a malicious website causes a victim's web browser to perform an unwanted action on a different, trusted website where the user is currently authenticated.\nIn this context, the vulnerability allows an unauthenticated remote attacker to force administrative or authorized users to execute unintended actions within the PowerPress plugin interface without their knowledge or consent.\nThe primary risk implication is the potential for unauthorized state-changing operations, such as modifying plugin settings, altering podcast feeds, or potentially injecting malicious scripts if the target action involves input processing.\nThe exploitation requirement involves the attacker enticing an authenticated user, typically an administrator, to click a specially crafted link or visit a malicious site while they have an active session in the WordPress dashboard.\nSuccessful exploitation compromises the integrity of the plugin configuration and may lead to further security degradation depending on the specific administrative actions the attacker can force the victim to perform.",
"technicalDetails": "The vulnerability originates from a lack of anti-CSRF tokens (often implemented as nonces in the WordPress environment) for sensitive administrative actions within the PowerPress Podcasting plugin. Anti-CSRF tokens are critical security measures designed to verify that a request was intentionally initiated by the legitimate user rather than a forged request from a third-party source.\nIn the affected versions (n/a through 11.17.9), the plugin fails to properly validate the origin of requests that modify plugin-specific configurations. Because the application relies solely on the user's browser-stored authentication cookies to authorize requests, any request containing valid session identifiers is processed as legitimate by the backend server.\nThe attack flow proceeds as follows: 1) The attacker crafts a malicious request targeting a specific plugin endpoint responsible for modifying settings or performing administrative tasks. 2) The attacker embeds this request into a webpage or a link, designed to be executed automatically (e.g., via a hidden image source, an auto-submitting form, or an AJAX call). 3) The attacker tricks an authenticated administrator into interacting with this malicious content while their session with the WordPress instance is active. 4) The victim's browser automatically appends the relevant session cookies to the forged request sent to the server. 5) The server validates the session cookies as authentic and processes the forged command, effectively granting the attacker the ability to perform operations under the authority of the victim.\nSince the WordPress environment heavily relies on HTTP requests for plugin management, this vulnerability allows for unauthorized manipulation of plugin parameters. If the target functions allow for file uploads, redirection, or configuration updates, the attacker could effectively change how podcasts are served, redirect traffic to external sources, or disable security features associated with the plugin. This vulnerability does not require the attacker to bypass authentication directly; instead, it leverages the authenticated status of the legitimate user to bypass the intended authorization checks. The absence of cryptographically secure, request-specific tokens allows for successful cross-domain forgery, making it a critical concern for site administrators who rely on the integrity of the PowerPress plugin configuration."
}