Podlove Vulnerabilities and Affected Products
Vulnerabilities associated with Podlove Web Player.
Products
Clear product- Podlove Podcast Publisher9 vulnerabilities
- podlove_podcast_publisher6 vulnerabilities
- Podlove Subscribe button2 vulnerabilities
- Podlove Web Player2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-35710MEDIUM | WordPress Podlove Web Player plugin <= 5.7.3 - Sensitive Data Exposure vulnerabilityExposure of Sensitive Information to an Unauthorized Actor vulnerability in Podlove Podlove Web Player.This issue affects Podlove Web Player: from n/a through 5.7.3. CWE-200Jun 8, 2024 | CVSS5.3v3.1 | EPSS0.365% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-29788MEDIUM | WordPress Podlove Web Player plugin <= 5.7.1 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Podlove Podlove Web Player allows Stored XSS.This issue affects Podlove Web Player: from n/a through 5.7.1. CWE-79Mar 27, 2024 | CVSS6.5v3.1 | EPSS0.331% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |