Junglewise Threat Intelligence

CVE-2026-1382: freshlabs fresh Podcaster Stored XSS in freshpodcaster shortcode

CVE-2026-1382 · Severity: medium · CVSS 6.4 · Published 2026-07-11

Executive brief

The fresh Podcaster plugin for WordPress, which is used to manage and display podcast content, contains a security flaw that allows users with basic contributor access to inject malicious scripts into website pages. When other users or administrators visit these affected pages, the hidden scripts will execute in their browsers. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.

Technical details

The fresh Podcaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on user-supplied attributes within the 'freshpodcaster' shortcode. The vulnerability exists in versions up to and including 1.0.7. An authenticated attacker with contributor-level permissions or higher can exploit this by injecting arbitrary web scripts into a post or page using the shortcode. These scripts are then stored and executed in the context of any user's browser who views the affected page. The flaw is located in the shortcode handling logic within public-facing display files.

Affected products

  • freshlabs fresh Podcaster up to, and including, 1.0.7

Timeline

  • 2026-07-11: advisory: NVD publication date

References