WordPress Podlove Podcast Publisher Plugin <= 3.8.3 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2023-25472
8.8HIGH
Summary
The Podlove Podcast Publisher plugin for WordPress is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability in versions up to 3.8.3. This flaw allows an attacker to trick users into executing unwanted actions on the website without their consent. By leveraging this vulnerability, malicious entities can manipulate user interactions, potentially leading to unauthorized changes or data exposure. It is crucial for website administrators to patch this vulnerability to ensure the security and integrity of their systems.
Affected Version(s)
Podlove Podcast Publisher <= 3.8.3
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
yuyudhn (Patchstack Alliance)