SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-13729

MEDIUM · CVSS 4.3 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-08-01 · Last synced 2026-08-31

CyberRota Analysis

AI-Generated

The Podlove Podcast Publisher plugin for WordPress prior to version 4.5.3 is vulnerable due to the lack of nonce validation on administrative create and delete actions, enabling attackers to exploit cross-site request forgery (CSRF) to create or delete records. This vulnerability poses a significant risk to WordPress sites using the plugin, as it can lead to unauthorized changes to podcast records. Administrators of affected WordPress installations should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-13729
Severity
MEDIUM
CVSS
4.3
EPSS
0.10%
WordPress

Original NVD Description

The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on some of its administrative create and delete actions, allowing attackers to create rogue records or delete legitimate ones via a forged request (CSRF) when a logged-in administrator is tricked into visiting a crafted page.