Lucene search

K
wpvulndbWpvulndbWPVDB-ID:86B3BF75-5407-4692-B520-C4EF9D672952
HistoryFeb 06, 2024 - 12:00 a.m.

Podlove Podcast Publisher < 4.0.12 - Missing Authorization to Settings Import

2024-02-0600:00:00
wpscan.com
4
podlove podcast publisher
wordpress
vulnerability
missing authorization
data modification

6.9 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

28.6%

Description The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the init() function in all versions up to, and including, 4.0.11. This makes it possible for unauthenticated attackers to import the plugin’s settings.

CPENameOperatorVersion
eq4.0.12

6.9 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

28.6%

Related for WPVDB-ID:86B3BF75-5407-4692-B520-C4EF9D672952