Known CVE
WordPress Podlove Podcast Publisher <3.5.6 - SQL Injection
WordPress Podlove Podcast Publisher plugin before 3.5.6 is susceptible to SQL injection. The Social & Donations module, not activated by default, adds the REST route /services/contributor/(?P<id>[\d]+) and takes id and category parameters as arguments. Both parameters can be exploited, thereby potentially enabling an attacker to obtain sensitive information, modify data, and/or execute unauthorized administrative operations.
CVE-2021-24666
Critical2021CVSS 9.8CWE-89
cve2021 · sqli · wordpress · wp-plugin · wp · podlove-podcasting-plugin-for-wordpress · wpscan · podlove
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website