Input validation vulnerability in Buzzsprout Podcasting 1.8.3

The Buzzsprout Podcasting plugin for WordPress has a security issue in versions before and including 1.8.3. Attackers with contributor-level access or higher can inject malicious web scripts into pages which will be executed when any user views the page. This is due to the plugin not properly checking the data that users provide and not escaping the output.

Detected in:

Buzzsprout Podcasting fixed vulnerable versions: >= * <= 1.8.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.