Input validation vulnerability in Podlove Podcast Publisher 4.1.13

The plugin called Podlove Podcast Publisher, used for WordPress websites, has a security issue called Cross-Site Request Forgery. This problem affects versions up to 4.1.13. The reason for this vulnerability is because the plugin does not properly check for a security code called “nonce” in the ‘get’, ‘update’, ‘create’, and ‘delete’ functions. This means that people who are not logged into the website can change the templates and even run code remotely if they can trick the website administrator into clicking on a link.

Detected in:

Podlove Podcast Publisher open vulnerable versions: >= * <= 4.1.13

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.