CVE-2017-12949: Podlove Podcast Publisher

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

lib\modules\contributors\contributor_list_table.php in the Podlove Podcast Publisher plugin 2.5.3 and earlier for WordPress has SQL injection in the orderby parameter to wp-admin/admin.php, exploitable through CSRF.

Affected products

  • Podlove Podlove Podcast Publisher: version 2.5.3 only

Published 2017-08-18. Last modified 2026-06-17.