CVE-2025-0554: Podlove Podcast Publisher <= 4.1.25 - Authenticated (Admin+) Stored Cross-Site Scripting via Feed Name
The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Feed Name value in version <= 4.1.25 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfilteredhtml has been disabled.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0554?
CVE-2025-0554 is rated as a high-severity vulnerability due to the potential for authenticated attackers to exploit it.
How do I fix CVE-2025-0554?
To fix CVE-2025-0554, you should update the Podlove Podcast Publisher plugin to version 4.1.26 or later.
Who is affected by CVE-2025-0554?
Users of the Podlove Podcast Publisher plugin for WordPress running version 4.1.25 or earlier are vulnerable to CVE-2025-0554.
What type of vulnerability is CVE-2025-0554?
CVE-2025-0554 is identified as a Stored Cross-Site Scripting (XSS) vulnerability.
What can attackers do with CVE-2025-0554?
Authenticated attackers with administrator-level access can inject malicious scripts through the Feed Name value, potentially compromising site security.