Podlove maintains a focused portfolio of WordPress-integrated podcast publishing and distribution plugins that serve content creators and publishers across a distributed ecosystem. The vendor's vulnerability exposure concentrates in its flagship products—the Podcast Publisher and Subscribe Button plugins—and recurs through application-layer weakness classes including cross-site scripting, cross-site request forgery, SQL injection, missing authorization, and code injection that are characteristic of web-facing WordPress extensions. A meaningful share of disclosed vulnerabilities reach serious severity, reflecting the access to user data, podcast metadata, and administrative functions that these plugins command. Defenders should treat updates for these widely installed content-distribution components as routine, especially in multi-author publishing environments where privilege boundaries matter; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Podlove over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24666CRITICAL The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P< | Sep 27, 2021 | 9.8 | 43 | NO | YES |
CVE-2016-10942CRITICAL The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id parameter exploitable via CSRF. | Sep 13, 2019 | 9.8 | 30 | NO | NO |
CVE-2024-43984HIGH Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue affects Podlove Podcast Publisher: from n/a through 4.1.13. | Oct 31, 2024 | 8.8 | 27 | NO | NO |
CVE-2023-25481HIGH Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Subscribe button plugin <= 1.3.7 versions. | May 23, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-25472HIGH Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher plugin <= 3.8.3 versions. | May 23, 2023 | 8.8 | 26 | NO | NO |
CVE-2024-32143HIGH Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.1.0. | Jun 11, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-1118HIGH The Podlove Subscribe button plugin for WordPress is vulnerable to UNION-based SQL Injection via the 'button' attribute of the podlove-subscribe-button shortcode in all versions up | Feb 7, 2024 | 8.8 | 24 | NO | NO |
CVE-2017-12949HIGH lib\modules\contributors\contributor_list_table.php in the Podlove Podcast Publisher plugin 2.5.3 and earlier for WordPress has SQL injection in the orderby parameter to wp-admin/a | Aug 18, 2017 | 8.8 | 24 | NO | NO |
CVE-2024-32139HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher | Apr 15, 2024 | 8.8 | 23 | NO | NO |
CVE-2024-52393HIGH Deserialization of Untrusted Data vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress.This issue affects Podlove Podcast Publisher: from | Nov 14, 2024 | 7.2 | 21 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Podlove.
Media articles that mention a CVE ID that affects a product developed by Podlove — matched by CVE ID, not by vendor name.