What is CVE-2026-13729?
The Podlove Podcast Publisher plugin before version 4.5.3 lacks nonce validation on some administrative create and delete actions. This allows attackers to forge requests (CSRF) to create rogue records or delete legitimate ones if a logged-in administrator is tricked into visiting a malicious link. Users should update the plugin to version 4.5.3 or later to mitigate this vulnerability.
Azərbaycanca: Podlove Podcast Publisher plaginində 4.5.3 versiyasından əvvəl bəzi idarəetmə əməliyyatları üçün nonce yoxlanışı aparılmır. Bu boşluq, administratorun saxta keçidə klikləməsi ilə CSRF hücumlarına səbəb olaraq, icazəsiz qeydlərin yaradılmasına və ya mövcud qeydlərin silinməsinə imkan verir. WordPress istifadəçiləri Podlove Podcast Publisher plaginini ən azı 4.5.3 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
What vulnerability was found in the Podlove Podcast Publisher plugin?
The plugin before version 4.5.3 lacks nonce validation on some administrative create and delete actions. This allows CSRF attacks to create rogue records or delete legitimate ones if a logged-in administrator is tricked into visiting a malicious link.
How can I protect against this CSRF vulnerability?
Users should update the Podlove Podcast Publisher plugin to version 4.5.3 or later to mitigate this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.