VYPR
Unrated severityNVD Advisory· Published Apr 7, 2023· Updated Apr 28, 2026

WordPress Podlove Podcast Publisher Plugin <= 3.8.2 is vulnerable to Cross Site Scripting (XSS)

CVE-2023-25046

Description

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Podlove Podlove Podcast Publisher plugin <= 3.8.2 versions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Admin-level stored XSS in Podlove Podcast Publisher plugin for WordPress allows arbitrary script execution via unsanitized input.

Vulnerability

The Podlove Podcast Publisher plugin for WordPress, versions 3.8.2 and earlier, contains a stored cross-site scripting (XSS) vulnerability [1]. This flaw affects authenticated users with administrator-level privileges who can inject malicious scripts via input fields that are not properly sanitized before being stored and later rendered in the admin interface.

Exploitation

An attacker must have administrator-level access to the WordPress instance where the vulnerable plugin is installed. Once authenticated as an admin, the attacker can inject arbitrary JavaScript payloads into plugin settings or podcast episode fields that are not sanitized. The injected script is then stored and executed when other admin users view the affected pages, leading to XSS [1].

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of another administrator's browser session. This can lead to session hijacking, forced administrative actions, or defacement, compromising the integrity and confidentiality of the WordPress site [1].

Mitigation

The vulnerability is fixed in version 4.5.0 of the Podlove Podcast Publisher plugin [1]. Users should update to this or a later version immediately. If updating is not possible, consider restricting admin access to trusted users only, as the vulnerability requires admin-level privileges.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.