Podlove
Podlove Podcast Publisher: vulnerabilidades y CVE
Podlove Podcast Publisher tiene 28 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE28
Últimos 12 meses6
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-75966 | Media (6.4) | 0.45% | — | 9 sept 2026 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'episode_contributor[..][..][comment]' Parameter in all versions up to, and including, 4.5.5 due to insufficient input… |
| CVE-2026-66615 | Alta (7.1) | 0.25% | — | 20 ago 2026 | Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions. |
| CVE-2026-16099 | Alta (8.8) | 1.1% | — | 16 ago 2026 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This… |
| CVE-2026-13729 | Media (4.3) | 0.14% | — | 1 ago 2026 | The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on some of its administrative create and delete actions, allowing attackers to create rogue records or delete legitimate ones… |
| CVE-2026-13001 | Crítica (9.8) | 3.8% | — | 14 jul 2026 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all versions up to, and including, 4.5.1.… |
| CVE-2026-32448 | Media (6.5) | 0.22% | — | 13 mar 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress allows Stored XSS.This issue affects… |
| CVE-2025-10147 | Crítica (9.8) | 0.94% | — | 23 sept 2025 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_as_original_file' function in all versions up to, and including, 4.2.6. This… |
| CVE-2025-58204 | Media (4.7) | 0.21% | — | 27 ago 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress allows Phishing.This issue affects Podlove Podcast Publisher: from n/a… |
| CVE-2024-13730 | Media (4.8) | 0.31% | — | 15 may 2025 | The Podlove Podcast Publisher WordPress plugin before 4.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even… |
| CVE-2024-13729 | Media (4.8) | 0.31% | — | 15 may 2025 | The Podlove Podcast Publisher WordPress plugin before 4.1.24 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even… |
| CVE-2025-1383 | Media (4.3) | 0.22% | — | 6 mar 2025 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.2. This is due to missing or incorrect nonce validation on the… |
| CVE-2025-0554 | Media (4) | 0.27% | — | 18 ene 2025 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Feed Name value in version <= 4.1.25 due to insufficient input sanitization and output escaping. This makes it… |
| CVE-2024-52393 | Alta (7.2) | 0.53% | — | 14 nov 2024 | Deserialization of Untrusted Data vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress.This issue affects Podlove Podcast Publisher: from n/a through <= 4.1.15. |
| CVE-2024-43984 | Alta (8.8) | 0.31% | — | 31 oct 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue affects Podlove Podcast Publisher: from n/a through 4.1.13. |
| CVE-2024-43983 | Media (5.4) | 0.29% | — | 18 sept 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Podlove Podlove Podcast Publisher allows Stored XSS.This issue affects Podlove Podcast Publisher: from n/a… |
| CVE-2024-32143 | Alta (8.8) | 0.44% | — | 11 jun 2024 | Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.1.0. |
| CVE-2024-32712 | Media (4.3) | 0.45% | — | 14 may 2024 | Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.14. |
| CVE-2024-32812 | Media (5.4) | 0.38% | — | 24 abr 2024 | Server-Side Request Forgery (SSRF) vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.11. |
| CVE-2024-32139 | Alta (8.8) | 0.96% | — | 15 abr 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.12. |
| CVE-2024-29915 | Media (6.1) | 0.40% | — | 27 mar 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Podlove Podlove Podcast Publisher allows Reflected XSS.This issue affects Podlove Podcast Publisher: from n/a through… |
| CVE-2024-1110 | Media (5.3) | 0.52% | — | 7 feb 2024 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init() function in all versions up to, and including, 4.0.11. This makes it… |
| CVE-2024-1109 | Media (5.3) | 0.55% | — | 7 feb 2024 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the init_download() and init() functions in all versions up to, and including, 4.0.11.… |
| CVE-2023-25472 | Alta (8.8) | 0.27% | — | 23 may 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher plugin <= 3.8.3 versions. |
| CVE-2023-25046 | Media (4.8) | 0.39% | — | 7 abr 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Podlove Podlove Podcast Publisher plugin <= 3.8.2 versions. |
| CVE-2021-24666 | Crítica (9.8) | 8.9% | — | 27 sept 2021 | The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P<id>[\d]+), takes an 'id' and 'category'… |
| CVE-2016-10942 | Crítica (9.8) | 2.0% | — | 13 sept 2019 | The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id parameter exploitable via CSRF. |
| CVE-2016-10941 | Media (6.1) | 1.2% | — | 13 sept 2019 | The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has XSS exploitable via CSRF. |
| CVE-2017-12949 | Alta (8.8) | 1.1% | — | 18 ago 2017 | lib\modules\contributors\contributor_list_table.php in the Podlove Podcast Publisher plugin 2.5.3 and earlier for WordPress has SQL injection in the orderby parameter to wp-admin/admin.php, exploitable through CSRF. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.