
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24637 is a SQL injection vulnerability in the PowerPress Podcasting WordPress plugin by Blubrry Podcasting, affecting all versions up to and including 11.15.10. The flaw allows authenticated users with Contributor-level privileges to inject malicious SQL queries via unvalidated input, potentially exposing sensitive database contents. It was reported by researcher Phat RiO on December 5, 2025, and published by Patchstack on June 15, 2026. The vulnerability carries a CVSS v3.1 base score of 8.5 (High), assigned by Patchstack (Patchstack).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning user-supplied input is not properly sanitized before being incorporated into SQL queries within the plugin (Patchstack). An authenticated attacker with at minimum Contributor-level access can craft malicious input to manipulate database queries, enabling unauthorized data retrieval. The attack vector is network-based, requires low privileges, no user interaction, and has low attack complexity, with a changed scope indicating potential impact beyond the plugin's immediate database context. Relevant attack patterns include classic SQL injection (CAPEC-66), blind SQL injection (CAPEC-7), and command-line execution through SQL injection (CAPEC-108).
Successful exploitation primarily impacts confidentiality, with a high rating for data exposure and a low rating for availability disruption, while integrity is not directly affected per the CVSS scoring (Patchstack). An attacker can exfiltrate sensitive data from the WordPress database — including user credentials, personal information, and site configuration — and may cause limited service disruption. The changed scope in the CVSS vector indicates that the impact can extend beyond the plugin itself to affect the broader WordPress installation and potentially other hosted sites sharing the same database.
' OR 1=1--, UNION-based, or time-based blind payloads) into the vulnerable parameter to manipulate the underlying database query.wp_users), site options, or other stored data.', UNION, SELECT, --, OR 1=1) in query parameters or POST body fields.UNION SELECT or time-delay functions like SLEEP().The vendor has released version 11.15.11 of the PowerPress Podcasting plugin, which patches this vulnerability; all users should update immediately (Patchstack). If immediate updating is not possible, site administrators should restrict Contributor-level account creation and review existing Contributor accounts for unauthorized access. Deploying a Web Application Firewall (WAF) with SQL injection rules — such as Patchstack's virtual patching — can provide interim protection until the plugin is updated.
Wordfence included this vulnerability in their weekly WordPress vulnerability report for the period of May 18–24, 2026, indicating it received attention from the broader WordPress security community. Patchstack, the discovering and reporting organization, classified the vulnerability as low priority in terms of likely exploitation impact despite the high CVSS score, noting it is unlikely to be exploited at scale.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."