{"id":"CVE-2016-10941","details":"The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has XSS exploitable via CSRF.","modified":"2026-04-10T03:50:26.010389Z","published":"2019-09-13T12:15:10.890Z","references":[{"type":"ADVISORY","url":"https://blog.ripstech.com/2016/the-state-of-wordpress-security/"},{"type":"ADVISORY","url":"https://github.com/podlove/podlove-publisher/blob/master/changelog.txt"},{"type":"ADVISORY","url":"https://wordpress.org/plugins/podlove-podcasting-plugin-for-wordpress/#developers"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/podlove/podlove-publisher","events":[{"introduced":"0"},{"fixed":"88cec05cdf070abe7f0a6ec95c31c39ba5fa68ac"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"2.3.16"}]}}],"versions":["1.10.10-alpha","1.10.11-alpha","1.10.14-alpha","1.10.15-alpha","1.10.16-alpha","1.10.17-alpha","1.10.18-alpha","1.10.19-alpha","1.10.20-alpha","1.10.21-alpha","1.10.22-alpha","1.10.23-alpha","1.10.3-alpha","1.10.4-alpha","1.10.5-alpha","1.10.6-alpha","1.10.7-alpha","1.10.8-alpha","1.10.9-alpha","1.11-alpha","1.11.1-alpha","1.11.2-alpha","1.9.10-alpha","1.9.11-alpha","1.9.12-alpha","1.9.3-alpha","1.9.4-alpha","1.9.5-alpha","1.9.6-alpha","1.9.8-alpha","1.9.9-alpha","2.0.0","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.1.0","2.1.1","2.1.2","2.1.3","2.2.0","2.3.0","2.3.1","2.3.10","2.3.11","2.3.12","2.3.13","2.3.14","2.3.15","2.3.2","2.3.3","2.3.4","2.3.5","2.3.6","2.3.7","2.3.8","2.3.9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-10941.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}