CVE-2024-6588: PowerPress Podcasting plugin by Blubrry <= 11.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via media_url Parameter
The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘mediaurl’ parameter in all versions up to, and including, 11.9.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6588?
CVE-2024-6588 is classified as a high severity vulnerability due to the potential for Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2024-6588?
To fix CVE-2024-6588, update the PowerPress Podcasting plugin to version 11.9.11 or later.
Which versions of the PowerPress Podcasting plugin are affected by CVE-2024-6588?
CVE-2024-6588 affects all versions of the PowerPress Podcasting plugin up to and including version 11.9.10.
What kind of attack does CVE-2024-6588 enable?
CVE-2024-6588 enables Reflected Cross-Site Scripting attacks through the ‘media_url’ parameter due to insufficient input sanitization.
What components are involved in CVE-2024-6588?
CVE-2024-6588 involves the PowerPress Podcasting plugin developed by Blubrry for WordPress.