CVE-2026-2988Disclosure

LOWCVSS 6.4 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'powerpress' and 'podcast' shortcodes in versions up to, and including, 11.15.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-08); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-08: 3Mentions · 2026-04-21: 1PoC Mentioned / Linked · 2026-04-21: 1Technical Details · 2026-04-08: 204-0804-21
Signal classification3 categories
Disclosure
250.0%
General
125.0%
PoC
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-083
Disclosure2General1
2026-04-211
PoC1
Full discourse4 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-2988-powerpress-version-11-15-15-medium-vulnerability-proof-of-concept CVE-2026-2988 #WordPress plugin #vulnerability powerpress #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The content links to a proof‑of‑concept for CVE‑2026‑2988, providing no further exploitation details, patches, or confirmation of active attacks.

    0000034
    6 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-2988 📊 Severity: 6.4 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-2988 #CVE-2026-2988 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/ZoEKm6bvmK

    Post summary

    A new medium‑severity Wordpress vulnerability (CVE-2026-2988) has been announced; no PoC, exploit details, active use, or patch information are provided.

    0000042
    123 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2988 Stored Cross-Site Scripting in Blubrry PowerPress Plugin for WordPress 11.15.15 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2988

    Post summary

    The text announces CVE-2026-2988, a stored XSS flaw in Blubrry PowerPress Plugin 11.15.15, without providing PoC, exploit details, or patches.

    0000053
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-2988 The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'powerpress' and 'podcast' shortcodes in versions up to, and including,… https://www.cve.org/CVERecord?id=CVE-2026-2988

    Post summary

    The post states that Blubrry PowerPress is vulnerable to stored XSS via specific shortcodes, but provides no evidence of exploitation, patch updates, or additional technical details.

    0000073
    57.0K followersView on X

Explore more