Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Podlove

First CVE: Aug 18, 2017Active for: 9 yearsTotal CVEs: 23
29.3
VTI Score
Low

Podlove maintains a focused portfolio of WordPress-integrated podcast publishing and distribution plugins that serve content creators and publishers across a distributed ecosystem. The vendor's vulnerability exposure concentrates in its flagship products—the Podcast Publisher and Subscribe Button plugins—and recurs through application-layer weakness classes including cross-site scripting, cross-site request forgery, SQL injection, missing authorization, and code injection that are characteristic of web-facing WordPress extensions. A meaningful share of disclosed vulnerabilities reach serious severity, reflecting the access to user data, podcast metadata, and administrative functions that these plugins command. Defenders should treat updates for these widely installed content-distribution components as routine, especially in multi-author publishing environments where privilege boundaries matter; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
1.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Podlove over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 18, 2017
8 years ago
Most Recent CVE
May 15, 2025
435 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-24666CRITICAL
The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P<
Sep 27, 20219.843NOYES
CVE-2016-10942CRITICAL
The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id parameter exploitable via CSRF.
Sep 13, 20199.830NONO
CVE-2024-43984HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue affects Podlove Podcast Publisher: from n/a through 4.1.13.
Oct 31, 20248.827NONO
CVE-2023-25481HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Subscribe button plugin <= 1.3.7 versions.
May 23, 20238.826NONO
CVE-2023-25472HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher plugin <= 3.8.3 versions.
May 23, 20238.826NONO
CVE-2024-32143HIGH
Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.1.0.
Jun 11, 20248.824NONO
CVE-2024-1118HIGH
The Podlove Subscribe button plugin for WordPress is vulnerable to UNION-based SQL Injection via the 'button' attribute of the podlove-subscribe-button shortcode in all versions up
Feb 7, 20248.824NONO
CVE-2017-12949HIGH
lib\modules\contributors\contributor_list_table.php in the Podlove Podcast Publisher plugin 2.5.3 and earlier for WordPress has SQL injection in the orderby parameter to wp-admin/a
Aug 18, 20178.824NONO
CVE-2024-32139HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher
Apr 15, 20248.823NONO
CVE-2024-52393HIGH
Deserialization of Untrusted Data vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress.This issue affects Podlove Podcast Publisher: from
Nov 14, 20247.221NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
57%
35%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network23 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (95.7%)
High1 (4.3%)
Unknown0 (0.0%)
User Interaction
None10 (43.5%)
Unknown0 (0.0%)
Required13 (56.5%)
Privileges Required
Low6 (26.1%)
High6 (26.1%)
None11 (47.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.3% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Podlove.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Podlove — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Podlove's Products

View all 4 CNAs →

Top CWEs