CVE-2026-75966: Podlove Podcast Publisher <= 4.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'episode_contributor[..][..][comment]' Parameter

Published Sep 9, 2026
·
Updated

The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'episodecontributor[..][..][comment]' Parameter in all versions up to, and including, 4.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The contributor comment is stored in a plugin-managed custom table, bypassing WordPress core's wpksespost filter, and the savepost hook fires without a nonce check, meaning any user who can edit posts can exploit this without further preconditions.

Affected Software

1 affected component
podlove Podlove Podcast Publisher<=4.5.5

Event History

Sep 9, 2026
CVE Published
via MITRE·03:28 AM
Data Sourced
via MITRE·03:28 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated WordPress user with Contributor-level access or higher can exploit it, provided they can edit posts. No additional user interaction or preconditions are required for the attacker to save the payload.

2

Are sites affected by default?

Sites using Podlove Podcast Publisher version 4.5.5 or earlier are affected if users with Contributor-level or higher access can edit posts. The vulnerable contributor comment is stored in a plugin-managed custom table rather than being filtered by WordPress core's wp_kses_post mechanism.

3

What happens after a malicious comment is saved?

The injected script is stored and executes in the browser whenever a user accesses the affected page. This can expose or alter content available in the viewing user's browser context.

4

What can be done if updating is not immediately possible?

Restrict post-editing access to trusted users, particularly Contributor accounts, and review contributor-comment content associated with editable posts for suspicious script payloads. Removing untrusted Contributor-level accounts reduces the set of users able to exploit the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203