CVE-2026-94682: WordPress Podcast Importer SecondLine plugin <= 1.5.6 - Cross Site Scripting (XSS) vulnerability
Published Sep 23, 2026
·Updated
Contributor Cross Site Scripting (XSS) in Podcast Importer SecondLine <= 1.5.6 versions.
Affected Software
1 affected component
SecondLine Podcast Importer SecondLine<=1.5.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Podcast Importer SecondLine pluginto a version that resolves this vulnerability.Fixed in 1.5.8
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is described as contributor XSS, so an attacker needs Contributor-level access to the affected WordPress site. User interaction is also required for exploitation.
2
Which plugin versions are affected?
Podcast Importer SecondLine versions 1.5.6 and earlier are affected.
3
What impact could successful exploitation have?
The supplied CVSS vector indicates low confidentiality, integrity, and availability impact, with scope changed. Successful XSS could allow actions or data access in another user’s browser context.