Sceawere

Vulnerability Detail

CVE-2026-97319UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

PowerPress Stored XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.8
Creation Date
1d ago
Vendor
Unknown
Product
PowerPress Podcasting plugin by Blubrry
Attack Type
CWE-79 Cross-Site Scripting (XSS)
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribute before outputting it in a page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.8",
  "pubDate": "2026-09-27T06:17:23.293Z",
  "pubdate": "2026-09-27T06:17:23.293Z",
  "executiveSummary": "The PowerPress Podcasting plugin for WordPress, in versions prior to 11.17.2, contains a Stored Cross-Site Scripting (XSS) vulnerability.\nThis vulnerability exists because the plugin fails to properly sanitize and escape block attributes before rendering them on a page.\nThe flaw allows authenticated users with a role of contributor or higher to inject malicious JavaScript payloads into post or page content.\nWhen a victim, such as an administrator or another user, views the affected content, the injected script executes within the context of their session.\nThis can lead to unauthorized actions, credential theft, session hijacking, or site-wide defacement, depending on the privileges of the targeted user.\nThe vulnerability is limited to authenticated users; however, the ability for lower-privileged users (contributors) to escalate their impact represents a significant security risk to the WordPress environment.",
  "technicalDetails": "The vulnerability originates from inadequate input validation and output encoding within the PowerPress block rendering logic.\nSpecifically, the plugin processes custom block attributes without performing necessary sanitization to strip executable code or encoding to ensure data is treated as plain text rather than active HTML/script content.\nThe attack vector involves a user with the 'contributor' role or higher navigating to the WordPress block editor and inserting a crafted PowerPress block.\nThe attacker manipulates the block's attributes to inject a malicious payload—typically JavaScript contained within <script> tags or via event handler attributes like 'onmouseover' or 'onerror'.\nUpon saving or publishing the post, this payload is stored persistently within the WordPress database associated with the post_content.\nWhen the affected page or post is subsequently rendered, the server outputs the unsanitized block attribute directly into the Document Object Model (DOM) of the browser.\nBecause the output is not sanitized, the victim's browser interprets the injected payload as trusted code and executes it within the security context of the origin (the WordPress site).\nThis process bypasses any potential client-side security mechanisms because the malicious script is delivered as part of the server's legitimate HTML response.\nSuccessful exploitation allows the attacker to execute arbitrary JavaScript. For an attacker targeting an administrator, this could result in the creation of new administrative accounts, modification of site settings, or the exfiltration of sensitive session cookies.\nThe vulnerability affects all versions of the PowerPress Podcasting plugin prior to 11.17.2.\nThe exploit is inherently stored, meaning the payload persists indefinitely until the vulnerable post is removed or the plugin is updated, allowing for deferred or multiple-victim exploitation."
}
CVE-2026-97319: PowerPress Stored XSS Vulnerability (MEDIUM Severity, CVSS: 6.8) | Sceawere