CyberRota Analysis
AI-GeneratedThe PowerPress Podcasting plugin for WordPress versions prior to 11.16.11 is vulnerable due to insufficient sanitization and escaping of certain Podcast Episode settings. This flaw enables users with a Contributor role to execute Stored Cross-Site Scripting (XSS) attacks, potentially compromising site integrity even when the unfiltered_html capability is restricted. WordPress site administrators, especially those using the PowerPress plugin, should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Podcast Episode settings, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.