CVE-2024-9230: PowerPress Podcasting < 11.9.18 - Author+ XSS via Podcast URL
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could allow author and above users to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9230?
CVE-2024-9230 has a medium severity rating due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-9230?
To fix CVE-2024-9230, update the Blubrry PowerPress Podcasting plugin to version 11.9.18 or later.
Who is affected by CVE-2024-9230?
Users with author or higher roles of the Blubrry PowerPress Podcasting plugin prior to version 11.9.18 are affected by CVE-2024-9230.
What type of attack does CVE-2024-9230 enable?
CVE-2024-9230 enables Stored Cross-Site Scripting attacks due to insufficient sanitisation and escaping of settings.
Is there a known exploitation method for CVE-2024-9230?
Yes, CVE-2024-9230 can be exploited by injecting malicious scripts into podcast settings by authorized users.