CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-43984

CVSS 9.6v3.1pub. 2024-10-31upd. 2025-03-19

Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue affects Podlove Podcast Publisher: from n/a through 4.1.13.

🤖 AI Analysis
How it works

The attacker prepares a malicious website or crafted link containing an HTTP request that performs a dangerous operation on behalf of a logged-in user of the plugin. The plugin does not sufficiently verify whether the request originates from a trusted source (missing or bypassed CSRF token). After tricking the victim — for example, a WordPress administrator — into visiting the malicious site, the request is executed in their context, leading to code injection and arbitrary code execution on the server side.

Impact

An attacker can gain full control over the server hosting the WordPress site, including reading, modifying, or deleting data and installing malicious software. The vulnerability enables a breach of confidentiality, integrity, and availability of the system to the highest degree.

Mitigation & patch

The Podlove Podcast Publisher plugin should be immediately updated to a version higher than 4.1.13. Detailed information about available patches can be found in the vendor's references and in the Patchstack database.

Who is affected

Podlove Podcast Publisher in versions from the beginning of the project through 4.1.13 inclusive (from n/a through 4.1.13).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Podlove Podcast Publisher

    APP
    Podlove
    < 4.1.14
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2024-52393CRITICAL9.1PL ✓same product

RCE przez deserializację niezaufanych danych w Podlove Podcast Publisher

CVE-2021-24666CRITICAL9.8PL ✓same product

SQL Injection w module 'Social & Donations' wtyczki Podlove Podcast Publisher

CVE-2016-10942CRITICAL9.8PL ✓same product

SQL injection w Podlove Podcast Publisher dla WordPress via CSRF

CVE-2024-32712HIGH7.5same product

Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Pu...

CVE-2024-32139HIGH8.5same product

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Podlove ...