CVE-2024-13729: Podlove Podcast Publisher < 4.1.24 - Admin+ Stored XSS
The Podlove Podcast Publisher WordPress plugin before 4.1.24 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13729?
CVE-2024-13729 has a high severity rating due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-13729?
To fix CVE-2024-13729, update the Podlove Podcast Publisher plugin to version 4.1.24 or later.
Who is affected by CVE-2024-13729?
CVE-2024-13729 affects users of the Podlove Podcast Publisher WordPress plugin version before 4.1.24.
What type of attack does CVE-2024-13729 allow?
CVE-2024-13729 allows high privilege users to perform Stored Cross-Site Scripting attacks.
What are the consequences of CVE-2024-13729?
The consequences of CVE-2024-13729 include potential unauthorized script execution in user browsers.