Executive brief
The Podlove Podcast Publisher plugin for WordPress, which helps users manage and publish podcast episodes, contains a security flaw that could allow an attacker to modify podcast data. By tricking a logged-in administrator into clicking a malicious link, an attacker can remotely create or delete podcast contributors, groups, and roles. This could lead to unauthorized changes in how a podcast is managed or the loss of legitimate administrative records.
Technical details
The Podlove Podcast Publisher plugin for WordPress fails to implement nonce validation on several administrative actions related to contributor, group, and role management. This lack of CSRF protection allows a remote attacker to perform unauthorized create and delete operations by inducing an authenticated administrator to visit a specially crafted webpage. The vulnerability is rooted in the plugin's administrative backend and can result in the modification or deletion of database records. The issue is resolved in version 4.5.3.
Affected products
- Podlove Podlove Podcast Publisher < 4.5.3
Timeline
- 2026-07-20: disclosed
- 2026-08-01: advisory: NVD publication date
- 2026-08-01: patched: Fixed in version 4.5.3