Podlove Podcast Publisher
podlove-podcasting-plugin-for-wordpress · eklenti
Podlove Podcast Publisher için bilinen güvenlik açıkları. Sitenizde bu bileşenin hangi sürümünün çalıştığını WP Lens ile saniyede öğrenin.
23 bilinen açık
3 kritik · 2 kayıt için istismar kodu yayımlanmış · son kayıt 9 Eyl 2026
Güvenlik açıkları
- Kritik 9.8
Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter
- Kritik 9.8
Podlove Podcast Publisher <= 4.2.6 - Unauthenticated Arbitrary File Upload
- Kritik 9.8
The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id parameter exploitable via
- Yüksek 8.8
Podlove Podcast Publisher <= 4.5.3 - Authenticated (Contributor+) PHP Object Injection to Arbitrary File Deletion via 'unfurl_data' Parameter
- Yüksek 8.8
WordPress Podlove Podcast Publisher plugin <= 4.1.13 - CSRF to Remote Code Execution (RCE) vulnerability
- Yüksek 8.8
WordPress Podlove Podcast Publisher plugin <= 4.1.0 - Broken Access Control vulnerability
- Yüksek 8.8
WordPress Podlove Podcast Publisher plugin <= 4.0.12 - SQL Injection vulnerability
- Yüksek 8.8
WordPress Podlove Podcast Publisher Plugin <= 3.8.3 is vulnerable to Cross Site Request Forgery (CSRF)
- Yüksek 7.2
WordPress Podlove Podcast Publisher plugin <= 4.1.15 - Admin+ Remote Code Execution (RCE) vulnerability
- Yüksek 7.1
WordPress Podlove Podcast Publisher plugin <= 4.5.4 - Cross Site Scripting (XSS) vulnerability
- Orta 6.5
WordPress Podlove Podcast Publisher plugin <= 4.3.3 - Cross Site Scripting (XSS) vulnerability
- Orta 6.4
Podlove Podcast Publisher <= 4.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'episode_contributor[..][..][comment]' Parameter
- Orta 6.1
WordPress Podlove Podcast Publisher plugin <= 4.0.9 - Reflected Cross Site Scripting (XSS) vulnerability
- Orta 6.1
The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has XSS exploitable via CSRF.
- Orta 5.4
WordPress Podlove Podcast Publisher plugin <= 4.1.13 - Cross Site Scripting (XSS) vulnerability
- Orta 5.4
WordPress Podlove Podcast Publisher plugin <= 4.0.11 - Server Side Request Forgery (SSRF) vulnerability
- Orta 5.3
Podlove Podcast Publisher <= 4.0.11 - Missing Authorization to Settings Import
- Orta 5.3
Podlove Podcast Publisher <= 4.0.11 - Missing Authorization to Unauthenticated Data Export
- Orta 4.8
WordPress Podlove Podcast Publisher Plugin <= 3.8.2 is vulnerable to Cross Site Scripting (XSS)
- Orta 4.7
WordPress Podlove Podcast Publisher Plugin <= 4.2.5 - Open Redirection Vulnerability
- Orta 4.3
Podlove Podcast Publisher <= 4.2.2 - Cross-Site Request Forgery via ajax_transcript_delete Function
- Orta 4.3
WordPress Podlove Podcast Publisher plugin <= 4.0.14 - Broken Access Control vulnerability
- Orta 4.0
Podlove Podcast Publisher <= 4.1.25 - Authenticated (Admin+) Stored Cross-Site Scripting via Feed Name