Impact
The vulnerability is an unauthenticated Cross Site Scripting flaw in the WordPress Podlove Podcast Publisher plugin versions up to 4.5.4. An attacker can inject arbitrary HTML or JavaScript into pages rendered by the plugin, enabling the execution of malicious code in the browsers of site visitors. This can lead to session hijacking, cookie theft, defacement, or redirection to phishing sites. The weakness is a classic input validation issue, identified as CWE‑79.
Affected Systems
The affected systems are installations of the WordPress Podlove Podcast Publisher plugin developed by Eric Teubert. Any WordPress site running version 4.5.4 or earlier is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 classifies the issue as a medium severity vulnerability with significant impact on confidentiality, integrity, and availability. No EPSS score is available, so the current probability of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Since the flaw is unauthenticated and exploitable through the plugin’s web interface, an attacker can simply craft a malicious payload in a browser without needing privileged access.
OpenCVE Enrichment