Cross-Site Scripting Vulnerability in Penci Podcast by PenciDesign
CVE-2025-59584
6.5MEDIUM
What is CVE-2025-59584?
The Penci Podcast plugin by PenciDesign has a vulnerability that permits improper neutralization of user input during web page generation, leading to a DOM-based cross-site scripting (XSS) issue. This vulnerability affects all versions from n/a through 1.6, potentially allowing attackers to execute arbitrary scripts in the context of users' browsers. Proper measures should be taken to patch this vulnerability to ensure website security and user safety.
Affected Version(s)
Penci Podcast <= 1.6
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) (Patchstack Alliance)