Sceawere
Vulnerability Detail
CVE-2026-93775UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Podlove Podcast Publisher Stored XSS
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 2h ago
- Vendor
- eteubert
- Product
- Podlove Podcast Publisher
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Auphonic Webhook in all versions up to, and including, 4.5.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injection is triggered by submitting a request to the Auphonic webhook endpoint with any POST body where the status_string field is not the literal string 'Done', causing the full raw POST superglobal to be stored in the plugin log before any authentication key validation is performed.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-10T06:16:44.417Z",
"pubdate": "2026-10-10T06:16:44.417Z",
"executiveSummary": "The Podlove Podcast Publisher plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability residing within its Auphonic webhook integration.\nThe vulnerability affects all versions up to, and including, 4.5.6.\nThe issue stems from a failure to sanitize input or properly escape output when processing incoming POST requests to the Auphonic webhook endpoint.\nUnauthenticated attackers can inject arbitrary JavaScript into the plugin's internal logs, which is subsequently rendered within the WordPress administrative interface.\nThis allows for the execution of malicious scripts whenever an authorized user views the affected logging pages.\nThe primary risk implications include potential session hijacking, unauthorized administrative actions, and the compromise of data accessible to logged-in WordPress users.\nExploitation is trivial and requires no authentication, as the vulnerable code path executes prior to the validation of authentication tokens or API keys.\nSuccessful exploitation depends on the attacker's ability to trigger a webhook request with a specific payload that bypasses the 'Done' status check, forcing the plugin to write malicious raw POST data to its persistent storage.",
"technicalDetails": "The root cause of this vulnerability is improper handling of HTTP POST requests directed at the plugin's Auphonic webhook endpoint. The plugin architecture fails to implement adequate input sanitization or output encoding mechanisms for the data received within the POST superglobal.\nSpecifically, the vulnerability is triggered when a POST request is sent to the webhook endpoint where the 'status_string' field does not equate to the literal string 'Done'. Upon receiving such a request, the plugin prematurely logs the entire raw POST superglobal data to its internal storage logs before performing any meaningful security checks, such as verifying the validity of an Auphonic authentication key.\nBecause the plugin stores the raw contents of the POST body—which may contain arbitrary characters and script tags—without sanitizing them, this data is effectively stored as 'persistent' XSS payload within the WordPress database. When an administrator or privileged user subsequently navigates to the plugin's logs section, the WordPress interface renders the stored log entries.\nThe attack flow is as follows: 1) An unauthenticated attacker crafts a malicious HTTP POST request targeting the Podlove Podcast Publisher webhook endpoint. 2) The attacker embeds a JavaScript payload within one of the POST parameters (or the body) while ensuring the 'status_string' parameter is intentionally set to something other than 'Done'. 3) The plugin processes the request and identifies the status mismatch, leading to a logging routine that saves the full, unescaped POST superglobal into the plugin's log database. 4) The malicious script is now persisted on the server. 5) A victim (typically a site administrator) accesses the plugin's log dashboard, causing the stored payload to execute within the context of the administrator's browser session.\nThe post-exploitation impact is severe. Since the script executes within the administrative dashboard, the attacker can perform actions with the privileges of the victim, such as creating new administrative accounts, modifying plugin settings, exfiltrating sensitive site information, or redirecting users to malicious domains. The vulnerability is characterized by its lack of authentication, its reliance on a persistent storage mechanism, and the elevation of client-side code execution to administrative-level impact."
}