The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribute before outputting it in a page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. This vulnerability affects WordPress installations with the PowerPress Podcasting plugin, particularly those with users having contributor roles [truncated]
The PowerPress Podcasting plugin by Blubrry for WordPress has a Stored Cross-Site Scripting vulnerability via the 'embed' Episode Meta Field. This vulnerability affects all versions up to, and including, 11.16.8. The vulnerability allows authenticated attackers with author-level access and above to inject arbitrary web scripts. The scripts will execute when a user accesses an injected page. The embed valu [truncated]
The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'powerpress' and 'podcast' shortcodes in versions up to, and including, 11.15.15. This vulnerability is due to insufficient input sanitization and output escaping, allowing authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user [truncated]