Junglewise Threat Intelligence

CVE-2026-24637: Blubrry PowerPress Podcasting SQL injection in Contributor functions

CVE-2026-24637 · Severity: high · CVSS 8.5 · Published 2026-06-15

Executive brief

PowerPress Podcasting is a popular WordPress plugin used to manage and publish podcasts. A security flaw allows users with 'Contributor' level access to execute unauthorized database commands. This could lead to the theft of sensitive site information or disruption of website operations.

Technical details

A SQL injection vulnerability (CWE-89) exists in the PowerPress Podcasting plugin for WordPress in versions up to and including 11.15.10. The flaw is located in a component accessible to users with Contributor-level permissions, where input is improperly neutralized before being used in an SQL query. An authenticated attacker can exploit this to perform unauthorized database queries, potentially leading to data exfiltration or limited impact on availability. The issue has been addressed in version 11.15.11.

Affected products

  • Blubrry Podcasting PowerPress Podcasting <= 11.15.10

Timeline

  • 2025-12-05: other: Reported by researcher Phat RiO
  • 2026-05-20: patched: Version 11.15.11 released
  • 2026-06-15: advisory: NVD and Patchstack advisories published

References