Junglewise Threat Intelligence

CVE-2026-13729: Podlove Podcast Publisher CSRF in contributor and role management

CVE-2026-13729 · Severity: info · CVSS 4.3 · Published 2026-08-01

Executive brief

The Podlove Podcast Publisher plugin for WordPress, which helps users manage and publish podcast episodes, contains a security flaw that could allow an attacker to modify podcast data. By tricking a logged-in administrator into clicking a malicious link, an attacker can remotely create or delete podcast contributors, groups, and roles. This could lead to unauthorized changes in how a podcast is managed or the loss of legitimate administrative records.

Technical details

The Podlove Podcast Publisher plugin for WordPress fails to implement nonce validation on several administrative actions related to contributor, group, and role management. This lack of CSRF protection allows a remote attacker to perform unauthorized create and delete operations by inducing an authenticated administrator to visit a specially crafted webpage. The vulnerability is rooted in the plugin's administrative backend and can result in the modification or deletion of database records. The issue is resolved in version 4.5.3.

Affected products

  • Podlove Podlove Podcast Publisher < 4.5.3

Timeline

  • 2026-07-20: disclosed
  • 2026-08-01: advisory: NVD publication date
  • 2026-08-01: patched: Fixed in version 4.5.3

References

Related threats