Podlove Web Player

Podlove Web Player has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 3 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 1 high. 2024 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 1 of the records (33%). Other recurring categories include Deserialization Of Untrusted Data, Missing Authorization.

Every one of the 3 issues recorded for Podlove Web Player has a vendor fix available, so running the current release closes all known holes.

3 independent researchers contributed these findings, one record each. Podlove Web Player is installed on roughly 4,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all Podlove Web Player vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.5CVE-2026-24385

Podlove Web Player <= 5.9.1 - Authenticated (Contributor+) PHP Object Injection

Read the full analysis

Vulnerability Records

3 records
Plugin Profile
Latestv5.9.2

Podlove Web Player

gerritvanaaken

Author

gerritvanaaken

3.7(14)
74/100
Last Updated
2026-01-02 (8mo ago)
Active Installs
4,000+
Downloads
197,517
Requires WP
4.9.6+
Requires PHP
7.2+
Tested up to
WP 6.8.8
Created
2012-07-03 (14y ago)

Podlove Web Player is a HTML5 based web player for audio and video media files that is optimized and extended for the specific needs of podcasters. It has a native integration with Podlove Publisher, can be used as a shortcode and also plays well with Gutenberg Blocks. Made for Podcasters Podcast Chapters Transcripts Sharing & Embedding Download integrated Audio Controls, including playback speed Supports multiple audio file formats Supports live streams Theming & Templating The Player is fully customizable in terms of Theme colors Font family and weight Templates and appearance Subscribe Button Integration Customizable Podcast Clients Integration in the Player Usage There are basically four ways to use the Podlove Web Player: 1 Manual WordPress Shortcode Use a simple shortcode in your posts and pages, and the Podlove Web Player will appear, playing any media file you want to assign. Basic usage: [podlove-web-player theme="default" config="default" title="My episode title" subtitle="Episode Subtitle" poster="/files/path/to/poster.png" chapters="/files/path/to/chapters.json" transcripts="/files/path/to/transcripts.json" playlist="/files/path/to/playlist.json" src="http://mysite.com/mymedia.mp3" size="1337" show="My show title" duration="03:33" ] Use an existing post with a media enclosure that is provided from plugins like Blubrry: [podlove-web-player theme="default" config="default" post="1234" ] Or in case you have our Podlove Publisher installed: [podlove-web-player theme="default" config="default" publisher="1234" ] 2 Using WordPress Gutenberg Blocks You can choose between different references, like Podlove Publisher, Blocks or you can add the meta data manually. Right now the latter option is limited to a limited set of attributes, this will be expanded in further releases. 3 Automatic Integration with Podcasting Engines If you are using Podlove Publisher you should be able to select it in the Publisher Player settings. In case you are still using Blubrry you can simply enable the automatic insertions on enclosures in the settings and choose the position. Help & Support If you encounter any issue with the plugin or want to request a specific feature please reach out to our Podlove Community.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C