CyberRota Analysis
AI-GeneratedThe Podlove Podcast Publisher plugin for WordPress prior to version 4.5.3 is vulnerable due to the lack of nonce validation on administrative create and delete actions, enabling attackers to exploit cross-site request forgery (CSRF) to create or delete records. This vulnerability poses a significant risk to WordPress sites using the plugin, as it can lead to unauthorized changes to podcast records. Administrators of affected WordPress installations should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Podlove Podcast Publisher WordPress plugin before 4.5.3 does not perform nonce validation on some of its administrative create and delete actions, allowing attackers to create rogue records or delete legitimate ones via a forged request (CSRF) when a logged-in administrator is tricked into visiting a crafted page.