CVE-2025-31436: WordPress Blubrry PowerPress Podcasting plugin MultiSite add-on plugin <= 0.1.1 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Angelo Mandato Blubrry PowerPress Podcasting plugin MultiSite add-on powerpress-multisite allows Reflected XSS.This issue affects Blubrry PowerPress Podcasting plugin MultiSite add-on: from n/a through <= 0.1.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31436?
CVE-2025-31436 is considered a medium severity vulnerability due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2025-31436?
To fix CVE-2025-31436, update the Blubrry PowerPress Podcasting plugin MultiSite add-on to a version later than 0.1.1.
What does CVE-2025-31436 affect?
CVE-2025-31436 affects the Blubrry PowerPress Podcasting plugin MultiSite add-on up to version 0.1.1.
How can CVE-2025-31436 impact my website?
Exploiting CVE-2025-31436 can lead to unauthorized script execution within the user's browser, compromising sensitive data.
Is CVE-2025-31436 a widespread issue?
The impact of CVE-2025-31436 largely depends on the usage of the affected Blubrry PowerPress Podcasting plugin across WordPress sites.