Podcast Importer SecondLine [podcast-importer-secondline] < 1.3.8
unknown
[en] The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, which could allow SQL injection attacks to be performed by imported a malicious podcast file
- Affected:
- up to 1.3.8
- Fixed in:
- 1.3.8
- Disclosed:
- Apr 11, 2022
CVE-2022-1023 on NVD →
Podcast Importer SecondLine < 1.3.8 - SQL Injection
high
The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, which could allow SQL injection attacks to be performed by imported a malicious podcast file.
- CVSS:
- 7.2
- Affected:
- up to 1.3.8
- Fixed in:
- 1.3.8
- Disclosed:
- Mar 21, 2022
CVE-2022-1023 on NVD →
Podcast Importer SecondLine [podcast-importer-secondline] < 1.1.5
unknown
[en] Server-side request forgery (SSRF) in the Podcast Importer SecondLine (podcast-importer-secondline) plugin 1.1.4 for WordPress via the podcast_feed parameter in a secondline_import_initialize action to the secondlinepodcastimport page.
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.5
- Disclosed:
- Jul 7, 2021
CVE-2020-24149 on NVD →
Podcast Importer SecondLine <= 1.1.4 - Server-Side Request Forgery
medium
Server-side request forgery (SSRF) in the Podcast Importer SecondLine (podcast-importer-secondline) plugin 1.1.4 and below for WordPress via the podcast_feed parameter in a secondline_import_initialize action to the secondlinepodcastimport page.
- CVSS:
- 6.5
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.5
- Disclosed:
- Apr 13, 2021
CVE-2020-24149 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database