CVE-2026-97319: PowerPress < 11.17.2 - Contributor+ Stored XSS via Podcast Player Block
Published Sep 27, 2026
·Updated
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribute before outputting it in a page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
1 affected component
Blubrry PowerPress Podcasting plugin<11.17.2
Event History
Sep 27, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
Description
Frequently Asked Questions
1
Which users can exploit this issue?
A user with the WordPress contributor role or any higher-privileged role can exploit it. The issue requires the ability to create or modify content containing the affected Podcast Player block attribute.
2
What versions are affected?
PowerPress Podcasting versions before 11.17.2 are affected. Updating to version 11.17.2 or later addresses the vulnerable behavior.
3
What is the impact of successful exploitation?
An authorized contributor-level user could store malicious script content in a page. The script could execute when another user views the affected page.