CVE-2026-23798 PUBLISHED

WordPress PowerPress Podcasting plugin <= 11.15.10 - PHP Object Injection vulnerability

Assigner: Patchstack
Reserved: 16.01.2026 Published: 05.03.2026 Updated: 05.03.2026

Deserialization of Untrusted Data vulnerability in blubrry PowerPress Podcasting powerpress allows Object Injection.This issue affects PowerPress Podcasting: from n/a through <= 11.15.10.

Product Status

Vendor blubrry
Product PowerPress Podcasting
Versions Default: unaffected
  • affected from n/a to <= 11.15.10 (incl.)

Credits

  • Muhammad Yudha - DJ | Patchstack Bug Bounty Program finder

References

Problem Types

  • Deserialization of Untrusted Data CWE

Impacts

  • Object Injection