VendorsPodlovepodlove_podcast_publisher2.5.3
Vulnerabilities

Podlove Podcast Publisher 2.5.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2017-12949
lib\modules\contributors\contributor_list_table.php in the Podlove Podcast Publisher plugin 2.5.3 and earlier for WordPress has SQL injection in the orderby parameter to wp-admin/admin.php, exploitable through CSRF.
Published 2017-08-18 · Modified
8.8EPSS 0.011