Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Podlove Podcast Publisher — Vulnerabilities & Security Advisories 24

All 24 CVE vulnerabilities found in Podlove Podcast Publisher, with AI-generated Chinese analysis, references, and POCs.

This page documents known security weaknesses associated with Podlove Podcast Publisher, an open-source WordPress plugin used for podcast publishing. It aggregates vulnerability records identified by security researchers and public databases, covering incidents reported from 2015 to the present. Visitors can track the vendor’s advisory history, understand the nature of specific weakness classes such as cross-site scripting or improper access control, and look up the complete vulnerability history of the product to assess its current security posture. The collection focuses on publicly disclosed issues that may impact users running self-hosted podcast networks or individual podcasters using this specific plugin. Entries include details on affected versions, severity ratings where available, and references to upstream patches or workarounds. This resource aims to provide transparency for system administrators and developers who need to evaluate risks before updating or continuing to use the software. By centralizing these findings, it supports informed decision-making regarding mitigation strategies and compliance requirements. The data is sourced from official changelogs, third-party security audits, and automated scanning results. Users are encouraged to verify findings against the latest official documentation, as remediation efforts may have addressed older issues in recent releases. This aggregate view does not replace vendor-specific security bulletins but complements them by offering a historical perspective on the plugin’s security evolution. Regular monitoring of this page helps stakeholders stay aware of emerging threats and past incidents that could inform future development or deployment decisions.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-66615 WordPress Podlove Podcast Publisher plugin <= 4.5.4 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2026-08-20
CVE-2026-16099 Podlove Podcast Publisher <= 4.5.3 - Authenticated (Contributor+) PHP Object Injection to Arbitrary File Deletion via 'unfurl_data' Parameter CWE-502 8.8 High 2026-08-16
CVE-2026-13729 Podlove Podcast Publisher < 4.5.3 - Podcast Contributor/Group/Role Creation and Deletion via CSRF - - 2026-08-01
CVE-2026-13001 Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter CWE-20 9.8 Critical 2026-07-14
CVE-2026-32448 WordPress Podlove Podcast Publisher plugin <= 4.3.3 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2026-03-13
CVE-2025-10147 Podlove Podcast Publisher <= 4.2.6 - Unauthenticated Arbitrary File Upload CWE-434 9.8 Critical 2025-09-23
CVE-2025-58204 WordPress Podlove Podcast Publisher Plugin <= 4.2.5 - Open Redirection Vulnerability CWE-601 4.7 Medium 2025-08-27
CVE-2024-13730 Podlove Podcast Publisher < 4.2.1 - Admin+ Stored XSS 4.8AI Medium AI 2025-05-15
CVE-2024-13729 Podlove Podcast Publisher < 4.1.24 - Admin+ Stored XSS 4.8AI Medium AI 2025-05-15
CVE-2025-1383 Podlove Podcast Publisher <= 4.2.2 - Cross-Site Request Forgery via ajax_transcript_delete Function CWE-352 4.3 Medium 2025-03-06
CVE-2025-0554 Podlove Podcast Publisher <= 4.1.25 - Authenticated (Admin+) Stored Cross-Site Scripting via Feed Name CWE-79 4.4 Medium 2025-01-18
CVE-2024-52393 WordPress Podlove Podcast Publisher plugin <= 4.1.15 - Admin+ Remote Code Execution (RCE) vulnerability CWE-82 9.1 Critical 2024-11-14
CVE-2024-43984 WordPress Podlove Podcast Publisher plugin <= 4.1.13 - CSRF to Remote Code Execution (RCE) vulnerability CWE-352 9.6 Critical 2024-10-31
CVE-2024-43983 WordPress Podlove Podcast Publisher plugin <= 4.1.13 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-09-17
CVE-2024-32143 WordPress Podlove Podcast Publisher plugin <= 4.1.0 - Broken Access Control vulnerability CWE-862 4.3 Medium 2024-06-11
CVE-2024-32712 WordPress Podlove Podcast Publisher plugin <= 4.0.14 - Broken Access Control vulnerability CWE-862 7.5 High 2024-05-09
CVE-2024-32812 WordPress Podlove Podcast Publisher plugin <= 4.0.11 - Server Side Request Forgery (SSRF) vulnerability CWE-918 5.4 Medium 2024-04-24
CVE-2024-32139 WordPress Podlove Podcast Publisher plugin <= 4.0.12 - SQL Injection vulnerability CWE-89 8.5 High 2024-04-15
CVE-2024-29915 WordPress Podlove Podcast Publisher plugin <= 4.0.9 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2024-03-27
CVE-2024-1110 Podlove Podcast Publisher <= 4.0.11 - Missing Authorization to Settings Import CWE-862 5.3 Medium 2024-02-07
CVE-2024-1109 Podlove Podcast Publisher <= 4.0.11 - Missing Authorization to Unauthenticated Data Export CWE-862 5.3 Medium 2024-02-07
CVE-2023-25472 WordPress Podlove Podcast Publisher Plugin <= 3.8.3 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 4.3 Medium 2023-05-23
CVE-2023-25046 WordPress Podlove Podcast Publisher Plugin <= 3.8.2 is vulnerable to Cross Site Scripting (XSS) CWE-79 5.9 Medium 2023-04-07
CVE-2021-24666 Podlove Podcast Publisher < 3.5.6 - Unauthenticated SQL Injection CWE-89 9.8 - 2021-09-27

All 24 known CVE vulnerabilities affecting Podlove Podcast Publisher with full Chinese analysis, references, and POCs where available.