
PowerPress Podcasting plugin by Blubrry Security & Risk Analysis
wordpress.org/plugins/powerpressNo. 1 Podcasting plugin for WordPress.
Is PowerPress Podcasting plugin by Blubrry Safe to Use in 2026?
Generally Safe
Score 88/100PowerPress Podcasting plugin by Blubrry has a strong security track record. Known vulnerabilities have been patched promptly.
The PowerPress plugin exhibits a mixed security posture. While the static analysis indicates a significant effort towards securing entry points with no unprotected AJAX handlers or REST API routes, and a strong presence of nonce and capability checks, there are underlying concerns. The high number of dangerous functions, specifically `unserialize`, coupled with a substantial percentage of flows with unsanitized paths, including one high-severity taint flow, presents a notable risk. This suggests potential vulnerabilities where deserialization of untrusted input could lead to code execution or other harmful actions if not handled meticulously by the application logic consuming these flows.
The plugin's vulnerability history is a significant concern, with a large number of known CVEs (19 in total) across several high-impact categories including deserialization, CSRF, SSRF, unrestricted uploads, and XSS. Although there are currently no unpatched vulnerabilities, the sheer volume and types of past issues indicate a recurring pattern of complex security flaws. The last reported vulnerability in early 2026 suggests the possibility of recent, though now patched, issues, reinforcing the need for continued vigilance. While the current version shows some good security practices in its entry point protection, the historical trend and specific code signals like `unserialize` usage warrant caution and ongoing monitoring.
Key Concerns
- High number of dangerous functions (unserialize)
- High percentage of unsanitized paths in taint analysis
- One high severity taint flow
- Large historical vulnerability count (19 CVEs)
- Common vulnerability types: Deserialization, CSRF, SSRF, XSS
- Low percentage of properly escaped output
PowerPress Podcasting plugin by Blubrry Security Vulnerabilities
CVEs by Year
Severity Breakdown
19 total CVEs
PowerPress Podcasting plugin by Blubrry <= 11.15.10 - Authenticated (Contributor+) PHP Object Injection
Blubrry PowerPress <= 11.15.2 - Authenticated (Contributor+) Arbitrary File Upload via 'powerpress_edit_post'
PowerPress Podcasting <= 11.13.12 - Cross-Site Request Forgery
PowerPress Podcasting <= 11.13.11 - Authenticated (Contributor+) Server-Side Request Forgery
PowerPress Podcasting plugin by Blubrry <= 11.12.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
PowerPress Podcasting <= 11.12.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
PowerPress Podcasting <= 11.12.6 - Authenticated (Contributor+) Server-Side Request Forgery
PowerPress Podcasting <= 11.9.17 - Authenticated (Author+) Stored Cross-Site Scripting
PowerPress Podcasting <= 11.9.17 - Authenticated (Author+) Stored Cross-Site Scripting
Powerpress <= 11.9.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via skipto Shortcode
PowerPress Podcasting plugin by Blubrry <= 11.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via media_url Parameter
PowerPress <= 11.0.11 - Authenticated(Contributor+) Stored Cross-Site Scripting via Media URL
PowerPress <= 11.0.6 - Authenticated (Contributor+) Server-Side Request Forgery via wp_ajax_powerpress_media_info
PowerPress <= 10.2.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Feed[title]'
PowerPress <= 10.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
PowerPress <= 10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
PowerPress <= 8.3.7 - Arbitrary File Upload
PowerPress <= 6.0.4 - Reflected Cross-Site Scripting
PowerPress <= 6.0.0 - Cross-Site Scripting
PowerPress Podcasting plugin by Blubrry Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
PowerPress Podcasting plugin by Blubrry Attack Surface
AJAX Handlers 5
Shortcodes 10
WordPress Hooks 98
Scheduled Events 4
Maintenance & Trust
PowerPress Podcasting plugin by Blubrry Maintenance & Trust
Maintenance Signals
Community Trust
PowerPress Podcasting plugin by Blubrry Alternatives
Podcast Subscribe Buttons
podcast-subscribe-buttons
Add beautiful podcast subscribe buttons anywhere.
Anchor Episodes Index (Spotify for Podcasters)
anchor-episodes-index
A lightweight plugin that allows you to output an anchor.fm podcast player on your site that includes an episode index. Just add two URL's on the …
Simple Podcasting
simple-podcasting
Set up multiple podcast feeds using built-in WordPress posts. Includes a podcast block and podcast transcript block for the WordPress block editor.
Share Interactive Content from Spotify – By PulseShare
pulseshare
Share interactive content from Spotify on your website seamlessly without any embed codes.
WP Podcasts Manager
wp-podcasts-manager
Short Description: Import and display podcast episodes from RSS feeds including Spotify support.
PowerPress Podcasting plugin by Blubrry Developer Profile
1 plugin · 30K total installs
How We Detect PowerPress Podcasting plugin by Blubrry
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/powerpress/js/powerpress-admin.js/wp-content/plugins/powerpress/js/powerpress-player.js/wp-content/plugins/powerpress/js/powerpress-subscribe-shortcode.js/wp-content/plugins/powerpress/css/powerpress-admin.css/wp-content/plugins/powerpress/css/powerpress-player.css/wp-content/plugins/powerpress/css/powerpress-subscribe.css/wp-content/plugins/powerpress/images/player/play_video_default.jpg/wp-content/plugins/powerpress/js/powerpress-admin.js/wp-content/plugins/powerpress/js/powerpress-player.js/wp-content/plugins/powerpress/js/powerpress-subscribe-shortcode.jspowerpress/js/powerpress-admin.js?ver=powerpress/js/powerpress-player.js?ver=powerpress/js/powerpress-subscribe-shortcode.js?ver=powerpress/css/powerpress-admin.css?ver=powerpress/css/powerpress-player.css?ver=powerpress/css/powerpress-subscribe.css?ver=HTML / DOM Fingerprints
powerpress-playerpowerpress-subscribe-button<!-- Blubrry PowerPress Plugin --><!-- end Blubrry PowerPress Plugin -->data-powerpress-feeddata-powerpress-typePowerPressPlayerpowerpress_subscribe_shortcode_init[powerpress_subscribe][powerpress_player][powerpress_playlist]