Skip to content
Threat Feed
high advisory

CVE-2026-93775: Stored Cross-Site Scripting in Podlove Podcast Publisher

The Podlove Podcast Publisher plugin for WordPress contains an unauthenticated Stored XSS vulnerability in the Auphonic Webhook implementation, allowing for arbitrary script injection via crafted POST requests.

CVE search metadata

CVE search record: CVE-2026-93775. Severity: high. CVSS: 7.2. KEV: no. Product: Podlove Podcast Publisher (<= 4.5.6). Brief: CVE-2026-93775: Stored Cross-Site Scripting in Podlove Podcast Publisher. Brief link: https://feed.craftedsignal.io/briefs/2026-10-podlove-xss/

The Podlove Podcast Publisher plugin for WordPress (versions 4.5.6 and earlier) is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-93775. The flaw originates in the plugin's Auphonic Webhook endpoint, which lacks sufficient input sanitization and output escaping. When an unauthenticated attacker sends a POST request to this endpoint containing a status_string field that does not equal 'Done', the plugin logs the entire raw POST superglobal data. Because this data is stored in the application logs without authentication key validation, malicious JavaScript payloads can be persisted. These scripts execute in the browser of any user who subsequently views the logs, enabling potential session hijacking, unauthorized administrative actions, or credential theft. Given that the attack requires no authentication, it represents a high-risk vector for WordPress deployments using the affected plugin.

Impact

Successful exploitation allows unauthenticated attackers to execute arbitrary scripts in the context of an administrator or other user viewing the plugin logs. This can lead to the complete compromise of administrative accounts, unauthorized configuration changes, or the injection of further malicious content into the WordPress site.

Recommendation

  • Upgrade the Podlove Podcast Publisher plugin to the latest version beyond 4.5.6 immediately.
  • Until patching is possible, restrict access to the webhook endpoint or disable the Auphonic Webhook feature if not required.
  • Review WordPress access logs for anomalous POST requests directed at the plugin's webhook endpoint that deviate from expected patterns.

Immediate actions

Upgrade Podlove Podcast Publisher to the latest version.

IT Operations 48h

Mitigations

Block or restrict access to the Auphonic Webhook endpoint if not in active use.

immediate IT Operations

CVE-2026-93775

Detection coverage 1

Detects CVE-2026-93775 Exploitation - Unauthenticated POST to Auphonic Webhook with Suspicious status_string

high

Detects exploitation attempts targeting CVE-2026-93775 by identifying POST requests to the Auphonic webhook where the status_string field is not 'Done', which triggers the vulnerable logging mechanism.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →