What is CVE-2026-16293?
This vulnerability in the PowerPress Podcasting plugin for WordPress (versions before 11.16.11) allows Stored Cross-Site Scripting attacks due to insufficient sanitization of Podcast Episode settings. Even users with a Contributor role can exploit this when the `unfiltered_html` capability is disallowed. Immediate plugin update is required.
Azərbaycanca: Bu boşluq, WordPress üçün PowerPress Podcasting plugininin 11.16.11 versiyasından əvvəlki versiyalarında Podcast Episode parametrlərinin düzgün təmizlənməməsi səbəbindən Stored XSS hücumlarına imkan verir. Hücumçu Contributor kimi aşağı səviyyəli istifadəçi roluna malik olsa belə, `unfiltered_html` icazəsi bağlı olduqda belə zərərli kod yerləşdirə bilər. Plugin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which WordPress user role can exploit the CVE-2026-16293 vulnerability?
This vulnerability can be exploited by an attacker with a low-level user role such as Contributor, even when the `unfiltered_html` capability is disallowed.
What action should be taken to mitigate CVE-2026-16293?
The PowerPress Podcasting plugin must be updated immediately to the latest version (11.16.11 or higher).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.