Podlove Podcast Publisher

Podlove Podcast Publisher has 28 disclosed vulnerabilities in the WordSec catalog, reported between 2016 and 2026; all 28 are fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 9.9 out of 10. Severity breakdown: 4 critical and 7 high. 2024 was the busiest year with 10 disclosures.

The most common weakness is Cross-Site Scripting, behind 9 of the records (32%). Other recurring categories include Cross-Site Request Forgery (CSRF), Missing Authorization.

Every one of the 28 issues recorded for Podlove Podcast Publisher has a vendor fix available, so running the current release closes all known holes.

23 independent researchers contributed these findings, most of them (2) reported by Lucio Sá. Podlove Podcast Publisher is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

01234567891026.06.2012Today16.09.20168.8Podlove Podcast Publisher < 2.3.16 - Cross-Site Request Forgery to Cross-Site Scripting CVSS 8.8 · 16.09.201614.12.20168.8Podlove Podcast Publisher < 2.3.16 - SQL Injection CVSS 8.8 · 14.12.201607.08.20178.0Podlove Podcast Publisher <= 2.5.3 - Authenticated SQL Injection CVSS 8.0 · 07.08.201724.08.20219.8Podlove Podcast Publisher <= 3.5.5 - Unauthenticated SQL Injection CVSS 9.8 · 24.08.202103.02.20234.4Podlove Podcast Publisher <= 3.8.2 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 03.02.202310.02.20234.3Podlove Podcast Publisher <= 3.8.3 - Cross-Site Request Forgery CVSS 4.3 · 10.02.202306.02.20245.3Podlove Podcast Publisher <= 4.0.11 - Missing Authorization to Unauthenticated Data Export CVSS 5.3 · 06.02.20245.3Podlove Podcast Publisher <= 4.0.11 - Missing Authorization to Settings Import CVSS 5.3 · 06.02.202425.03.20246.1Podlove Podcast Publisher <= 4.0.9 - Reflected Cross-Site Scripting CVSS 6.1 · 25.03.202412.04.20249.9Podlove Podcast Publisher <= 4.0.12 - Authenticated (Contributor+) SQL Injection CVSS 9.9 · 12.04.20244.3Podlove Podcast Publisher <= 4.1.0 - Missing Authorization CVSS 4.3 · 12.04.202422.04.20244.3Podlove Podcast Publisher <= 4.0.14 - Cross-Site Request Forgery CVSS 4.3 · 22.04.20244.3Podlove Podcast Publisher <= 4.0.11 - Authenticated (Contributor+) Server-Side Request Forgery CVSS 4.3 · 22.04.202428.08.20248.8Podlove Podcast Publisher <= 4.1.13 - Cross-Site Request Forgery to Remote Code Execution CVSS 8.8 · 28.08.20246.4Podlove Podcast Publisher <= 4.1.13 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 28.08.202411.11.20247.2Podlove Podcast Publisher <= 4.1.15 - Authenticated (Admin+) Remote Code Execution CVSS 7.2 · 11.11.202417.01.20254.4Podlove Podcast Publisher <= 4.1.25 - Authenticated (Admin+) Stored Cross-Site Scripting via Feed Name CVSS 4.4 · 17.01.202503.03.20254.4Podlove Podcast Publisher <= 4.2.0 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 03.03.20254.4Podlove Podcast Publisher <= 4.1.23 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 03.03.202505.03.20254.3Podlove Podcast Publisher <= 4.2.2 - Cross-Site Request Forgery via ajax_transcript_delete Function CVSS 4.3 · 05.03.202527.08.20256.1Podlove Podcast Publisher <= 4.2.5 - Open Redirect CVSS 6.1 · 27.08.202522.09.20259.8Podlove Podcast Publisher <= 4.2.6 - Unauthenticated Arbitrary File Upload CVSS 9.8 · 22.09.202508.03.20266.4Podlove Podcast Publisher <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 08.03.202614.07.20269.8Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter CVSS 9.8 · 14.07.202601.08.20264.3Podlove Podcast Publisher < 4.5.3 - Cross-Site Request Forgery CVSS 4.3 · 01.08.202615.08.20268.8Podlove Podcast Publisher <= 4.5.3 - Authenticated (Contributor+) PHP Object Injection to Arbitrary File Deletion via 'unfurl_data' Parameter CVSS 8.8 · 15.08.202619.08.20267.2Podlove Podcast Publisher <= 4.5.4 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 19.08.202608.09.20266.4Podlove Podcast Publisher <= 4.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'episode_contributor[..][..][comment]' Parameter CVSS 6.4 · 08.09.2026

Strategic Overview

Avg CVSSMedium
6.5/ 10
Patch Coverage100%
Open

0

Fixed

28

Get automatic notifications for all Podlove Podcast Publisher vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.9CVE-2024-32139

Podlove Podcast Publisher <= 4.0.12 - Authenticated (Contributor+) SQL Injection

Read the full analysis

Vulnerability Records

28 records
2026-09-08 14:34CVE-2026-75966
6.4
Medium
Wordfence PRISMYes
2026-08-19 00:00CVE-2026-66615
7.2
High
darooYes
2026-08-15 16:09CVE-2026-16099
8.8
High
Wordfence PRISMYes
2026-08-01 00:00CVE-2026-13729
4.3
Medium
Ryan FabellaYes
2026-07-14 06:57CVE-2026-13001
9.8
Critical
Talal NasraddeenYes
2026-03-08 00:00CVE-2026-32448
6.4
Medium
zaimYes
2025-09-22 00:00CVE-2025-10147
9.8
Critical
Arkadiusz HydzikYes
2025-08-27 00:00CVE-2025-58204
6.1
Medium
Nguyen Xuan ChienYes
2025-03-05 21:31CVE-2025-1383
4.3
Medium
Abbas MamounYes
2025-03-03 00:00CVE-2024-13730
4.4
Medium
Bob MatyasYes
Showing 1–10 of 28 reports
Podlove Podcast Publisher banner
Latestv4.5.6

Podlove Podcast Publisher

Eric Teubert

Author

Eric Teubert

4.4(44)
88/100
Last Updated
2026-08-29 (15d ago)
Active Installs
3,000+
Downloads
596,627
Requires WP
5.7.0+
Requires PHP
8.0+
Tested up to
WP 7.1
Created
2012-06-26 (14y ago)

We started the Podlove Podcast Publisher project in 2012 because existing solutions were stuck in the past, complex and unwieldy. The Publisher helps you save time, worry less and provides a cutting edge listening experience for your audience. Official Site: podlove.org/podlove-podcast-publisher Getting Started Videos Starting fresh with Podlove Publisher: Migrating an existing podcast to Podlove Publisher: Compatible RSS Feeds The Publisher makes it easy to create highly expressive, efficient and super compatible podcast feeds with fine grained control over client behavior (e.g. GUID control to replace faulty episodes and for clients to reload) supporting all important meta data. Multi-Format Publishing The Publisher also makes multi-format publishing – embracing all modern and legacy audio and video codecs – a snap. By adopting simple file name conventions, the plugin allows the podcaster to provide individual feeds for certain use cases or audiences without adding work for the podcaster during the publishing process. Optimized Web Player The Publisher also comes integrated with the Podlove Web Player plugin and fully supports its advanced options including multiple audio (MP4 AAC, MP3, Vorbis, Opus) and video (MP4 H.264, WebM, Theora) format support for web browsers. This Web Player is fully HTML5 compatible and is ready for all touch based clients too. Metadata Galore Chapter Marks: The Publisher also makes it easy to publish chapter information in the player to make access to structured episodes even easier. Full support for linking directly to any part of your podcast on the web with instant playback included. Contributors: Bring your team and guests front and center. Manage contributors, including their names, avatars and web urls. Transcripts: WebVTT transcripts can be imported and even connected to your contributors. They are referenced in the RSS feed so they can be displayed by podcast apps. Seasons: Does your podcast have seasons? We got you covered with a dedicated “Seasons” module. Related Episodes: Manage and display related episodes on your website. Auphonic Integration Auphonic is your all-in-one audio post production webtool to achieve a professional quality result. We provide a first class integration module for ease of use and best automation experience. Flexible Templates To round it all up, a flexible template system enables you to published Podcasts in a defined fashion and change the style at any time without having to touch your individual postings later on. And this is just the beginning. We have a rich roadmap that will bring even more interesting features: integration with helpful services, much improved timeline metadata support (show notes) and much more. Further Reading Podlove Publisher Podlove Project Podlove Community Documentation Bug Tracker Donate Development of the plugin is an open process. The current version is available on GitHub Feel free to contribute and to fix errors or send improvements via GitHub. Requires PHP 8.0+

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C