Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue affects Podlove Podcast Publisher: from n/a through 4.1.13.
The attacker prepares a malicious website or crafted link containing an HTTP request that performs a dangerous operation on behalf of a logged-in user of the plugin. The plugin does not sufficiently verify whether the request originates from a trusted source (missing or bypassed CSRF token). After tricking the victim — for example, a WordPress administrator — into visiting the malicious site, the request is executed in their context, leading to code injection and arbitrary code execution on the server side.
An attacker can gain full control over the server hosting the WordPress site, including reading, modifying, or deleting data and installing malicious software. The vulnerability enables a breach of confidentiality, integrity, and availability of the system to the highest degree.
The Podlove Podcast Publisher plugin should be immediately updated to a version higher than 4.1.13. Detailed information about available patches can be found in the vendor's references and in the Patchstack database.
Podlove Podcast Publisher in versions from the beginning of the project through 4.1.13 inclusive (from n/a through 4.1.13).
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HPodlove Podcast Publisher
APPPodlove< 4.1.14
Related vulnerabilities
RCE przez deserializację niezaufanych danych w Podlove Podcast Publisher
SQL Injection w module 'Social & Donations' wtyczki Podlove Podcast Publisher
SQL injection w Podlove Podcast Publisher dla WordPress via CSRF
Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Pu...
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Podlove ...