CVE-2024-52393: WordPress Podlove Podcast Publisher plugin <= 4.1.15 - Admin+ Remote Code Execution (RCE) vulnerability
Published Nov 14, 2024
·Updated
Deserialization of Untrusted Data vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress.This issue affects Podlove Podcast Publisher: from n/a through <= 4.1.15.
Affected Software
3 affected components
podlove Podcast Publisher<=4.1.15
WordPress Podlove Podcast Publisher<=4.1.15
podlove Podlove Podcast Publisher WordPress<=4.1.15
Remediation
Information
Update to 4.1.17 or a higher version.
Event History
Nov 14, 2024
CVE Published
via MITRE·05:23 PM
Data Sourced
via MITRE·05:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-52393?
CVE-2024-52393 is classified with a high severity due to its potential to allow remote code execution.
2
How do I fix CVE-2024-52393?
To fix CVE-2024-52393, update Podlove Podcast Publisher to the latest version beyond 4.1.15.
3
Who is affected by CVE-2024-52393?
CVE-2024-52393 affects all versions of Podlove Podcast Publisher from an unspecified version up to and including 4.1.15.
4
What types of vulnerabilities does CVE-2024-52393 represent?
CVE-2024-52393 represents an improper neutralization of special elements vulnerability within a template engine.
5
Is CVE-2024-52393 related to WordPress?
Yes, CVE-2024-52393 is also applicable to the WordPress version of Podlove Podcast Publisher.