Executive brief
Podlove Podcast Publisher is a WordPress plugin used to manage and publish podcast content. The plugin contains an unauthenticated cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into pages. If a user visits a crafted page or clicks a malicious link, their session data or account could be compromised, or the plugin could be used to distribute malware to site visitors.
Technical details
The vulnerability is a reflected or stored cross-site scripting (XSS) flaw in Podlove Podcast Publisher versions up to 4.5.4 that does not properly sanitize user input. The XSS is unauthenticated, meaning no login credentials are required to trigger the vulnerability, though successful exploitation requires user interaction (e.g., clicking a malicious link or visiting a crafted page). An attacker can inject JavaScript code that executes in the context of a visitor's browser, enabling session hijacking, credential theft, or malware distribution. The vulnerability was patched in version 4.5.5.
Affected products
- Podlove org Podcast Publisher <=4.5.4
Timeline
- 2026-08-20: disclosed
- 2026-08-19: patched: Patched in version 4.5.5