CVE-2016-10942: Podlove Podcast Publisher
Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.
The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id parameter exploitable via CSRF.
Affected products
- Podlove Podlove Podcast Publisher: before 2.3.16 (fixed in 2.3.16)
Published 2019-09-13. Last modified 2026-06-17.