CVE-2023-25046: WordPress Podlove Podcast Publisher Plugin <= 3.8.2 is vulnerable to Cross Site Scripting (XSS)
Published Apr 7, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Podlove Podlove Podcast Publisher plugin <= 3.8.2 versions.
Affected Software
1 affected component
podlove Podlove Podcast Publisher WordPress<=3.8.2
Remediation
Information
Update to 3.8.3 or a higher version.
Event History
Apr 7, 2023
CVE Published
via MITRE·09:26 AM
Data Sourced
via MITRE·09:26 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-25046?
CVE-2023-25046 has a high severity level due to its potential for exploitation via stored Cross-Site Scripting (XSS).
2
How do I fix CVE-2023-25046?
To fix CVE-2023-25046, you should upgrade the Podlove Podcast Publisher plugin to version 3.8.3 or later.
3
Who is affected by CVE-2023-25046?
CVE-2023-25046 affects users of the Podlove Podcast Publisher plugin version 3.8.2 and earlier.
4
What type of vulnerability is CVE-2023-25046?
CVE-2023-25046 is a stored Cross-Site Scripting (XSS) vulnerability that requires admin authentication for exploitation.
5
What impact can CVE-2023-25046 have on my website?
Exploitation of CVE-2023-25046 could allow an attacker to execute malicious scripts in the context of an authenticated admin user.