Impact
The vulnerability permits an authenticated user with contributor level access or higher to store malicious scripts in the 'episode_contributor[..][..][comment]' field of the Podlove Podcast Publisher plugin. Because the input is not sanitized or escaped before being saved in a custom database table, these scripts are rendered on any page that displays contributor comments. Consequently, when a victim user loads such a page, arbitrary code runs in their browser context, enabling attackers to execute arbitrary code. The specific outcomes such as session cookie theft, identity impersonation, defacement, or further site‑wide attacks are not stated explicitly in the CVE description, but these consequences are commonly linked to XSS weaknesses and are therefore inferred.
Affected Systems
Any WordPress installation that has the Podlove Podcast Publisher plugin from vendor "eteubert" with version 4.5.5 or earlier is affected.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium severity risk, and the lack of an EPSS value or KEV listing suggests no known exploits yet. The flaw requires the attacker to be authenticated and possess edit post privileges; the save_post hook lacks a nonce check, so the exploit can be performed by any contributor‑level user without additional preconditions. Once the comment string is stored, all subsequent visitors to the impacted page will execute the injected script.
OpenCVE Enrichment