Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

Podlove Podcast Publisher — Vulnerabilities & Security Advisories 20

All 20 CVE vulnerabilities found in Podlove Podcast Publisher, with AI-generated Chinese analysis, references, and POCs.

This page catalogs known vulnerabilities associated with Podlove Podcast Publisher, a widely used WordPress plugin for podcast management, focusing on software weakness classes and security tags. It aggregates reports covering a range of criticality levels, including remote code execution, cross-site scripting, and improper access control issues, spanning from the plugin’s inception through recent disclosures. Visitors can use this resource to track vendor advisories over time, gaining insight into how the development team responds to reported issues and patches released. Users may also examine specific weakness classes to understand the nature of recurring security flaws within the codebase or investigate a particular product’s vulnerability history to assess long-term security posture. The data is organized to help developers, security researchers, and podcast creators evaluate risk exposure and prioritize remediation efforts. By consolidating disparate sources of vulnerability information, this page offers a centralized view of the security landscape for this specific toolset. It does not provide real-time monitoring or automated patching but serves as a historical record and reference point for security auditing. Readers are encouraged to cross-reference this information with official vendor channels for the most current mitigation guidance and configuration recommendations.

Vendor: Unknown

CVE IDTitleCVSSSeverityPublished
CVE-2026-32448 WordPress Podlove Podcast Publisher plugin <= 4.3.3 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2026-03-13
CVE-2025-10147 Podlove Podcast Publisher <= 4.2.6 - Unauthenticated Arbitrary File Upload CWE-434 9.8 Critical2025-09-23
CVE-2025-58204 WordPress Podlove Podcast Publisher Plugin <= 4.2.5 - Open Redirection Vulnerability CWE-601 4.7 Medium2025-08-27
CVE-2024-13730 Podlove Podcast Publisher < 4.2.1 - Admin+ Stored XSS 4.8AIMediumAI2025-05-15
CVE-2024-13729 Podlove Podcast Publisher < 4.1.24 - Admin+ Stored XSS 4.8AIMediumAI2025-05-15
CVE-2025-1383 Podlove Podcast Publisher <= 4.2.2 - Cross-Site Request Forgery via ajax_transcript_delete Function CWE-352 4.3 Medium2025-03-06
CVE-2025-0554 Podlove Podcast Publisher <= 4.1.25 - Authenticated (Admin+) Stored Cross-Site Scripting via Feed Name CWE-79 4.4 Medium2025-01-18
CVE-2024-52393 WordPress Podlove Podcast Publisher plugin <= 4.1.15 - Admin+ Remote Code Execution (RCE) vulnerability CWE-82 9.1 Critical2024-11-14
CVE-2024-43984 WordPress Podlove Podcast Publisher plugin <= 4.1.13 - CSRF to Remote Code Execution (RCE) vulnerability CWE-352 9.6 Critical2024-10-31
CVE-2024-43983 WordPress Podlove Podcast Publisher plugin <= 4.1.13 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2024-09-17
CVE-2024-32143 WordPress Podlove Podcast Publisher plugin <= 4.1.0 - Broken Access Control vulnerability CWE-862 4.3 Medium2024-06-11
CVE-2024-32712 WordPress Podlove Podcast Publisher plugin <= 4.0.14 - Broken Access Control vulnerability CWE-862 7.5 High2024-05-09
CVE-2024-32812 WordPress Podlove Podcast Publisher plugin <= 4.0.11 - Server Side Request Forgery (SSRF) vulnerability CWE-918 5.4 Medium2024-04-24
CVE-2024-32139 WordPress Podlove Podcast Publisher plugin <= 4.0.12 - SQL Injection vulnerability CWE-89 8.5 High2024-04-15
CVE-2024-29915 WordPress Podlove Podcast Publisher plugin <= 4.0.9 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2024-03-27
CVE-2024-1110 Podlove Podcast Publisher <= 4.0.11 - Missing Authorization to Settings Import CWE-862 5.3 Medium2024-02-07
CVE-2024-1109 Podlove Podcast Publisher <= 4.0.11 - Missing Authorization to Unauthenticated Data Export CWE-862 5.3 Medium2024-02-07
CVE-2023-25472 WordPress Podlove Podcast Publisher Plugin <= 3.8.3 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 4.3 Medium2023-05-23
CVE-2023-25046 WordPress Podlove Podcast Publisher Plugin <= 3.8.2 is vulnerable to Cross Site Scripting (XSS) CWE-79 5.9 Medium2023-04-07
CVE-2021-24666 Podlove Podcast Publisher < 3.5.6 - Unauthenticated SQL Injection CWE-89 9.8 -2021-09-27

All 20 known CVE vulnerabilities affecting Podlove Podcast Publisher with full Chinese analysis, references, and POCs where available.