First published: Tue Apr 25 2023(Updated: )
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Podlove Podlove Subscribe button plugin <= 1.3.7 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Podlove Subscribe Button | <1.3.9 |
Update to 1.3.9 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25479 is considered a medium severity vulnerability due to its potential for exploiting stored cross-site scripting.
To fix CVE-2023-25479, update the Podlove Subscribe Button plugin to version 1.3.9 or later.
CVE-2023-25479 is an authenticated stored cross-site scripting (XSS) vulnerability.
CVE-2023-25479 affects versions of the Podlove Subscribe Button plugin up to and including 1.3.7.
Administrators and users of websites utilizing the affected versions of the Podlove Subscribe Button plugin may be impacted by CVE-2023-25479.