CVE-2024-9227: PowerPress Podcasting < 11.9.18 - Author+ XSS
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could allow admin users to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9227?
CVE-2024-9227 has been rated as a high-severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-9227?
To fix CVE-2024-9227, update the Blubrry PowerPress Podcasting plugin to version 11.9.18 or higher.
Who is affected by CVE-2024-9227?
CVE-2024-9227 affects users of the Blubrry PowerPress Podcasting plugin on WordPress versions prior to 11.9.18.
What types of attacks can be performed due to CVE-2024-9227?
CVE-2024-9227 can allow attackers to perform Stored Cross-Site Scripting (XSS) attacks against admin users.
What are the implications of not addressing CVE-2024-9227?
Not addressing CVE-2024-9227 could lead to unauthorized malicious scripts being executed on a site's pages, compromising user data and site security.