CVE-2026-66615

WordPress Podlove Podcast Publisher plugin <= 4.5.4 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions.


We have discovered 1,595 live websites that are affected by CVE-2026-66615.

Run a Free Instant Scan




Affected Software

Product  Podlove Podcasting Plugin For Wordpress
Category Wordpress Plugins
Vulnerable Domains1,595 live websites (100% of Podlove Podcasting Plugin For Wordpress install base)
Vulnerable Versions
  • from 0 through 4.5.4
Vulnerable Versions Count46 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 20, 2026
  • Updated - Aug 20, 2026

Credits

  • daroo | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-66615
United States170 websites



Germany1,183 websites
Austria32 websites
Switzerland32 websites
France32 websites
Netherlands21 websites
Denmark16 websites
Spain14 websites
GB13 websites
Italy10 websites

Website Distribution by TLD

Number of websites using CVE-2026-66615
.de876 websites
.com229 websites
.org79 websites
.net69 websites
.eu34 websites
.at29 websites
.ch24 websites
.info23 websites
.nl22 websites
.fr14 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-66615

Top websites that are affected by CVE-2026-66615. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****************.de Germany**,***
*****.*********.net United States***,***
***.io United States***,***
*****************.org United States***,***
*********.es Germany***,***
************.de Germany***,***
********.com France***,***
**************************.de Germany***,***
***.de Germany***,***
******.*********.net Germany***,***
See full domain list

FAQ

CVE-2026-66615 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Podlove Podcasting Plugin For Wordpress
A total of 1,595 websites have been identified as vulnerable to CVE-2026-66615, based on global website indexing conducted by WebTechSurvey.
The Podlove Podcasting Plugin For Wordpress is affected by the CVE-2026-66615 vulnerability.
Podlove Podcasting Plugin For Wordpress versions up to and including 4.5.4 are vulnerable to CVE-2026-66615.