CVE-2025-32690: WordPress PowerPress Podcasting plugin <= 11.12.5 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Angelo Mandato PowerPress Podcasting allows DOM-Based XSS.This issue affects PowerPress Podcasting: from n/a through 11.12.5.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in blubrry PowerPress Podcasting powerpress allows DOM-Based XSS.This issue affects PowerPress Podcasting: from n/a through <= 11.12.5.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32690?
CVE-2025-32690 is classified as a high severity vulnerability due to its potential to allow DOM-based Cross-site Scripting (XSS).
How do I fix CVE-2025-32690?
To resolve CVE-2025-32690, update PowerPress Podcasting to a version later than 11.12.4 to mitigate the XSS vulnerability.
What products are affected by CVE-2025-32690?
CVE-2025-32690 affects PowerPress Podcasting versions up to and including 11.12.4.
What can attackers do exploiting CVE-2025-32690?
If exploited, CVE-2025-32690 allows attackers to execute arbitrary JavaScript code in the context of the user's browser.
Is CVE-2025-32690 specific to certain environments?
Yes, CVE-2025-32690 specifically affects the web environments using the vulnerable versions of PowerPress Podcasting.