Podigee WordPress Quick Publish – now with Gutenberg support!
Podigee WordPress Quick Publish – now with Gutenberg support! has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it remains unpatched as of August 2026. Their average CVSS score is 7.2, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Server-Side Request Forgery (SSRF), behind 1 of the records (100%).
The one issue recorded for Podigee WordPress Quick Publish – now with Gutenberg support! has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.
All of these findings were reported by Nabil Irawan. Podigee WordPress Quick Publish – now with Gutenberg support! is installed on roughly 700 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.3.10.
CVE-2026-39695Podigee <= 1.4.0 - Unauthenticated Sever-Side Request Forgery
Read the full analysisVulnerability Records

Podigee WordPress Quick Publish – now with Gutenberg support!
Author
podigee
This plugin let’s you fetch episode information from your Podigee podcast feed and copy it directly into the WordPress editor. It automatically adds a shortcode for the open-source Podigee Podcast Player as well. It is for Podigee users with premium plans – you can check here to see if your plan includes the use of this plugin. If you don’t need all your podcast’s meta information but only the Podigee web audio player, check out our free-for-all “Podigee Player Shortcode” plugin that uses shortcodes for rendering the Podigee Podcast in your WordPress post. Note: The plugin now works with the Gutenberg editor! Although the method on how you import your data into the post editor has changed. Please check the FAQs and the manual below. MIT License Copyright (c) 2021 Podigee Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the “Software”), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C