CVE-2026-104407: WordPress PowerPress Podcasting plugin <= 11.17.9 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Cross Site Request Forgery.This issue affects PowerPress Podcasting: from n/a through 11.17.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress PowerPress Podcasting pluginto a version that resolves this vulnerability.Fixed in 11.17.11
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The CVSS vector indicates that no attacker privileges are required, but user interaction is required. The issue is reachable over the network.
Which installations should be considered affected?
The reported affected range is PowerPress Podcasting versions through 11.17.9. The available data does not provide a lower bound for the affected version range.
What is the potential security impact?
The CVSS vector rates confidentiality, integrity, and availability impact as low. It also indicates a changed scope.