The PowerPress Podcasting plugin by Blubrry for WordPress has a Stored Cross-Site Scripting vulnerability via the 'embed' Episode Meta Field. This vulnerability affects all versions up to, and including, 11.16.8. The vulnerability allows authenticated attackers with author-level access and above to inject arbitrary web scripts. The scripts will execute when a user accesses an injected page. The embed valu [truncated]
The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'powerpress' and 'podcast' shortcodes in versions up to, and including, 11.15.15. This vulnerability is due to insufficient input sanitization and output escaping, allowing authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user [truncated]