Code Injection Vulnerability in Podlove Podcast Publisher
CVE-2024-43984

9.6CRITICAL

Key Information:

Vendor
WordPress
Vendor
CVE Published:
31 October 2024

Summary

A Cross-Site Request Forgery (CSRF) vulnerability found in Podlove Podcast Publisher allows malicious actors to perform code injection attacks. This security flaw affects versions of the Podlove Podcast Publisher up to and including 4.1.13, enabling unauthorized actions without proper user authentication. Websites utilizing this plugin may be at risk, allowing attackers to execute arbitrary code and potentially compromising the integrity of the system.

Affected Version(s)

Podlove Podcast Publisher <= 4.1.13

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

Credit

Muhammad Daffa (Patchstack Alliance)
.