CVE-2017-12949: Podlove Podcast Publisher
High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.
lib\modules\contributors\contributor_list_table.php in the Podlove Podcast Publisher plugin 2.5.3 and earlier for WordPress has SQL injection in the orderby parameter to wp-admin/admin.php, exploitable through CSRF.
Affected products
- Podlove Podlove Podcast Publisher: version 2.5.3 only
Published 2017-08-18. Last modified 2026-06-17.