← WordPress Vulnerabilities
WordPress security by component

Podlove Podcast Publisher

Podlove Podcast Publisher is a WordPress component with 16 published CVE records in this archive. The latest tracked vulnerability was published Jul 14, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: podlove-podcasting-plugin-for-wordpress

CVE-2026-13001: Podlove Podcast Publisher: Dangerous file upload

Podlove Podcast Publisher is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is <= 4.5.1.

PublishedJul 14, 2026
Known safe version> 4.5.1
Safe version
Jul 14, 2026 CVE-2026-13001
Podlove Podcast Publisher: Dangerous file upload
Podlove Podcast Publisher is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is <= 4.5.1.
> 4.5.1
CVE9.8
NVDPending
Mar 13, 2026 CVE-2026-32448
Podlove Podcast Publisher: Cross-site scripting
Podlove Podcast Publisher is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Sep 23, 2025 CVE-2025-10147
Podlove Podcast Publisher: Dangerous file upload
Podlove Podcast Publisher is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE9.8
NVDPending
Aug 27, 2025 CVE-2025-58204
Podlove Podcast Publisher: An open redirect
Podlove Podcast Publisher is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
See mitigation notes
CVE4.7
NVDPending
Mar 06, 2025 CVE-2025-1383
Podlove Podcast Publisher: Cross-site request forgery
Podlove Podcast Publisher is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Oct 31, 2024 CVE-2024-43984
Podlove Podcast Publisher: Code execution
Podlove Podcast Publisher is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.6
NVD8.8
Sep 18, 2024 CVE-2024-43983
Podlove Podcast Publisher: Cross-site scripting
Podlove Podcast Publisher is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jun 11, 2024 CVE-2024-32143
Podlove Podcast Publisher: A security weakness
Podlove Podcast Publisher is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD8.8
May 14, 2024 CVE-2024-32712
Podlove Podcast Publisher: A security weakness
Podlove Podcast Publisher is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD4.3
Apr 24, 2024 CVE-2024-32812
Podlove Podcast Publisher: Server-side request forgery
Podlove Podcast Publisher is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE5.4
NVD5.4
Apr 15, 2024 CVE-2024-32139
Podlove Podcast Publisher: SQL injection
Podlove Podcast Publisher is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVD8.8
Mar 27, 2024 CVE-2024-29915
Podlove Podcast Publisher: Cross-site scripting
Podlove Podcast Publisher is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
May 23, 2023 CVE-2023-25472
Podlove Podcasting Plugin For Wordpress: Cross-site request forgery
Podlove Podcasting Plugin For Wordpress is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
Apr 07, 2023 CVE-2023-25046
Podlove Podcasting Plugin For Wordpress: Cross-site scripting
Podlove Podcasting Plugin For Wordpress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Sep 13, 2019 CVE-2016-10942
Podlove Podcasting Plugin For Wordpress: SQL injection
Podlove Podcasting Plugin For Wordpress is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Sep 13, 2019 CVE-2016-10941
Podlove Podcasting Plugin For Wordpress: Cross-site scripting
Podlove Podcasting Plugin For Wordpress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1