What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress.This issue affects Podlove Podcast Publisher: from n/a through <= 4.1.15.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Deserialization of Untrusted Data vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress.This issue affects Podlove Podcast Publisher: from n/a through <= 4.1.15.
Explanation of Vulnerability in Simple Terms
Podlove Podcast Publisher versions 4.1.15 and earlier contain an improper access control vulnerability. An authenticated administrator can read, modify, or delete data across the entire site, including other users' content and settings. The vulnerability requires high-level privileges to exploit but affects confidentiality, integrity, and availability of the site.
What an attacker can do
Read, modify, or delete any site data including other users' content and configuration.
Potential impact on your site
A compromised admin account can expose, alter, or destroy all site data and settings.
Conditions required to exploit
Attacker must be authenticated as an administrator or high-privilege user.
Key dates
External resources
Related vulnerabilities