Cross-Site Scripting Vulnerability in Penci Podcast by PenciDesign
CVE-2025-59584

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 September 2025

What is CVE-2025-59584?

The Penci Podcast plugin by PenciDesign has a vulnerability that permits improper neutralization of user input during web page generation, leading to a DOM-based cross-site scripting (XSS) issue. This vulnerability affects all versions from n/a through 1.6, potentially allowing attackers to execute arbitrary scripts in the context of users' browsers. Proper measures should be taken to patch this vulnerability to ensure website security and user safety.

Affected Version(s)

Penci Podcast <= 1.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) (Patchstack Alliance)
.
CVE-2025-59584 : Cross-Site Scripting Vulnerability in Penci Podcast by PenciDesign