CVE-2026-66615: WordPress Podlove Podcast Publisher plugin <= 4.5.4 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Podlove Podcast Publisher pluginto a version that resolves this vulnerability.Fixed in 4.5.5
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability is described as unauthenticated, so an attacker does not need a WordPress account or prior privileges. The vector is network-accessible, but exploitation requires user interaction.
Which installations are known to be affected?
Podlove Podcast Publisher versions 4.5.4 and earlier are identified as affected. The provided information does not state whether any particular plugin configuration or WordPress setup is required.
What impact could successful exploitation have?
Successful XSS could affect confidentiality, integrity, and availability at a low impact level. Because the scope is changed, the impact may extend beyond the vulnerable plugin's own security authority.