CVE-2016-10941: Podlove Podcast Publisher

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has XSS exploitable via CSRF.

Affected products

  • Podlove Podlove Podcast Publisher: before 2.3.16 (fixed in 2.3.16)

Published 2019-09-13. Last modified 2026-06-17.