CVE-2026-32351

WordPress PowerPress Podcasting plugin <= 11.15.13 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in blubrry PowerPress Podcasting powerpress allows Stored XSS.This issue affects PowerPress Podcasting: from n/a through <= 11.15.13.


We have discovered 622 live websites that are affected by CVE-2026-32351.

Run a Free Instant Scan




Affected Software

Product  Powerpress
Category Wordpress Plugins
Vulnerable Domains622 live websites (50% of Powerpress install base)
Vulnerable Versions
  • from 0 through 11.15.13
Vulnerable Versions Count82 versions ( 95% of all versions)



Details

  • Published - Mar 13, 2026
  • Updated - Apr 1, 2026

Credits

  • Jitlada | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-32351
United States431 websites



Germany37 websites
Brazil22 websites
France14 websites
Canada11 websites
Netherlands10 websites
GB9 websites
Japan7 websites
Poland7 websites

Website Distribution by TLD

Number of websites using CVE-2026-32351
.com410 websites
.org48 websites
.net25 websites
.com.br20 websites
.de12 websites
.ca8 websites
.fr7 websites
.pl7 websites
.se5 websites
.nl5 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-32351

Top websites that are affected by CVE-2026-32351. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.com United States***,***
***************.com United States***,***
***************.org Netherlands***,***
**********.com United States***,***
************.com United States***,***
*********.com United States***,***
***********.co United States***,***
********************.com United States***,***
*******.com United States***,***
*********************.com United States***,***
See full domain list

FAQ

A total of 622 websites have been identified as vulnerable to CVE-2026-32351, based on global website indexing conducted by WebTechSurvey.
The Powerpress is affected by the CVE-2026-32351 vulnerability.
Powerpress versions up to and including 11.15.13 are vulnerable to CVE-2026-32351.