VendorsPodlovepodlove_podcast_publisherany version
Vulnerabilities

Podlove Podcast Publisher any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2021-24666
Podlove Podcast Publisher < 3.5.6 - Unauthenticated SQL Injection
Published 2021-09-27 · Modified
9.8EPSS 0.089
CVE-2016-10942
The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id parameter exploitable via CSRF.
Published 2019-09-13 · Modified
9.8EPSS 0.020
CVE-2024-43984
WordPress Podlove Podcast Publisher plugin <= 4.1.13 - CSRF to Remote Code Execution (RCE) vulnerability
Published 2024-10-31 · Analyzed
9.6EPSS 0.003
CVE-2024-52393
WordPress Podlove Podcast Publisher plugin <= 4.1.15 - Admin+ Remote Code Execution (RCE) vulnerability
Published 2024-11-14 · Modified
9.1EPSS 0.005
CVE-2024-32139
WordPress Podlove Podcast Publisher plugin <= 4.0.12 - SQL Injection vulnerability
Published 2024-04-15 · Modified
8.8EPSS 0.010
CVE-2024-32143
WordPress Podlove Podcast Publisher plugin <= 4.1.0 - Broken Access Control vulnerability
Published 2024-06-11 · Analyzed
8.8EPSS 0.004
CVE-2023-25472
WordPress Podlove Podcast Publisher Plugin <= 3.8.3 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-05-23 · Modified
8.8EPSS 0.003
CVE-2024-32712
WordPress Podlove Podcast Publisher plugin <= 4.0.14 - Broken Access Control vulnerability
Published 2024-05-09 · Modified
7.5EPSS 0.005
CVE-2024-29915
WordPress Podlove Podcast Publisher plugin <= 4.0.9 - Reflected Cross Site Scripting (XSS) vulnerability
Published 2024-03-27 · Modified
7.1EPSS 0.004
CVE-2024-43983
WordPress Podlove Podcast Publisher plugin <= 4.1.13 - Cross Site Scripting (XSS) vulnerability
Published 2024-09-17 · Analyzed
6.5EPSS 0.003
CVE-2016-10941
The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has XSS exploitable via CSRF.
Published 2019-09-13 · Modified
6.1EPSS 0.012
CVE-2023-25046
WordPress Podlove Podcast Publisher Plugin <= 3.8.2 is vulnerable to Cross Site Scripting (XSS)
Published 2023-04-07 · Modified
5.9EPSS 0.004
CVE-2024-32812
WordPress Podlove Podcast Publisher plugin <= 4.0.11 - Server Side Request Forgery (SSRF) vulnerability
Published 2024-04-24 · Modified
5.4EPSS 0.004
CVE-2024-1109
Podlove Podcast Publisher <= 4.0.11 - Missing Authorization to Unauthenticated Data Export
Published 2024-02-07 · Modified
5.3EPSS 0.005
CVE-2024-1110
Podlove Podcast Publisher <= 4.0.11 - Missing Authorization to Settings Import
Published 2024-02-07 · Modified
5.3EPSS 0.005
CVE-2024-13730
Podlove Podcast Publisher < 4.2.1 - Admin+ Stored XSS
Published 2025-05-15 · Analyzed
4.8EPSS 0.003
CVE-2024-13729
Podlove Podcast Publisher < 4.1.24 - Admin+ Stored XSS
Published 2025-05-15 · Analyzed
4.8EPSS 0.003
CVE-2025-0554
Podlove Podcast Publisher <= 4.1.25 - Authenticated (Admin+) Stored Cross-Site Scripting via Feed Name
Published 2025-01-18 · Analyzed
4.4EPSS 0.003
CVE-2025-1383
Podlove Podcast Publisher <= 4.2.2 - Cross-Site Request Forgery via ajax_transcript_delete Function
Published 2025-03-06 · Analyzed
4.3EPSS 0.002