{"id":"CVE-2026-97319","title":"The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribute before outputting it in a page, which could allow users with the contributor role and above to perform Stored Cros…","summary":"The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribute before outputting it in a page, which could allow users with the contributor role and above to perform Stored Cros…","severity":"none","cwe":["CWE-79"],"product":"PowerPress Podcasting plugin by Blubrry","affected":["powerpress_podcasting_plugin_by_blubrry < 11.17.2"],"published":"2026-09-27","updated":"2026-09-27","sourceUpdated":"2026-09-27T06:17:23.293","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-97319","references":[{"url":"https://wpscan.com/vulnerability/6ea7d2b5-8406-4efe-9b61-465af40d9a32/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-27T06:43:46.835Z","slug":"CVE-2026-97319","body":"## Overview\n\nThe PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribute before outputting it in a page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}