CVE-2026-104388: WordPress PowerPress Podcasting plugin <= 11.17.9 - Sensitive Data Exposure vulnerability
Missing Authorization vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Retrieve Embedded Sensitive Data.This issue affects PowerPress Podcasting: from n/a through 11.17.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress PowerPress Podcastingto a version that resolves this vulnerability.Fixed in 11.17.11
Event History
Frequently Asked Questions
Who can exploit this issue?
The CVSS vector indicates it can be exploited remotely over the network without authentication or user interaction. An attacker does not need privileges to attempt exploitation.
What is the likely security impact?
The stated impact is retrieval of embedded sensitive data. The supplied CVSS metrics indicate low confidentiality impact, with no integrity or availability impact.
Which installations are affected?
PowerPress Podcasting versions through 11.17.9 are affected. The provided information does not identify a safe fixed version or any configuration requirements.