CVE-2016-10941: Podlove Podcast Publisher
Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.
The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has XSS exploitable via CSRF.
Affected products
- Podlove Podlove Podcast Publisher: before 2.3.16 (fixed in 2.3.16)
Published 2019-09-13. Last modified 2026-06-17.