<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-93775 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-93775/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 07:51:46 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-93775/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-93775: Stored Cross-Site Scripting in Podlove Podcast Publisher</title><link>https://feed.craftedsignal.io/briefs/2026-10-podlove-xss/</link><pubDate>Sat, 10 Oct 2026 07:51:46 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-podlove-xss/</guid><description>The Podlove Podcast Publisher plugin for WordPress contains an unauthenticated Stored XSS vulnerability in the Auphonic Webhook implementation, allowing for arbitrary script injection via crafted POST requests.</description><content:encoded><![CDATA[<p>The Podlove Podcast Publisher plugin for WordPress (versions 4.5.6 and earlier) is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-93775. The flaw originates in the plugin's Auphonic Webhook endpoint, which lacks sufficient input sanitization and output escaping. When an unauthenticated attacker sends a POST request to this endpoint containing a <code>status_string</code> field that does not equal 'Done', the plugin logs the entire raw POST superglobal data. Because this data is stored in the application logs without authentication key validation, malicious JavaScript payloads can be persisted. These scripts execute in the browser of any user who subsequently views the logs, enabling potential session hijacking, unauthorized administrative actions, or credential theft. Given that the attack requires no authentication, it represents a high-risk vector for WordPress deployments using the affected plugin.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary scripts in the context of an administrator or other user viewing the plugin logs. This can lead to the complete compromise of administrative accounts, unauthorized configuration changes, or the injection of further malicious content into the WordPress site.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the Podlove Podcast Publisher plugin to the latest version beyond 4.5.6 immediately.</li>
<li>Until patching is possible, restrict access to the webhook endpoint or disable the Auphonic Webhook feature if not required.</li>
<li>Review WordPress access logs for anomalous POST requests directed at the plugin's webhook endpoint that deviate from expected patterns.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>xss</category><category>wordpress</category><category>cve-2026-93775</category></item></channel></rss>