CVE-2026-97319

NONE
Updated Sep 27, 2026
WordPress
Parameter Value
Affected Versions before 11.17.2
Vendor WordPress
Public PoC No

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribute before outputting it in a page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.