Description
PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the Freebox content field accessible through the theme customization interface (theme_freebox.php). Malicious JavaScript payloads injected into the Freebox content execute when users visit the application's home page.
Remediation
References
Related Vulnerabilities
WordPress Plugin AI ChatBot Cross-Site Scripting (4.9.6)
WordPress Plugin Theme Blvd Layout Builder Multiple Security Bypass Vulnerabilities (2.0.1)
RubyGems Improper Input Validation Vulnerability (CVE-2017-0900)
MySQL CVE-2012-3173 Vulnerability (CVE-2012-3173)
WordPress Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-17670)