AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-16293

MEDIUM · CVSS 6.8 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-04

CyberRota Analysis

AI-Generated

The PowerPress Podcasting plugin for WordPress versions prior to 11.16.11 is vulnerable due to insufficient sanitization and escaping of certain Podcast Episode settings. This flaw enables users with a Contributor role to execute Stored Cross-Site Scripting (XSS) attacks, potentially compromising site integrity even when the unfiltered_html capability is restricted. WordPress site administrators, especially those using the PowerPress plugin, should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-16293
Severity
MEDIUM
CVSS
6.8
EPSS
0.15%
WordPress

Original NVD Description

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Podcast Episode settings, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.