Description
Cross-Site Request Forgery (CSRF) vulnerability in Maulik Vora WP Podcasts Manager wp-podcasts-manager allows Cross Site Request Forgery.This issue affects WP Podcasts Manager: from n/a through <= 1.3.
Published: 2025-05-07
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Cross‑Site Request Forgery (CSRF) is a type of web‑application vulnerability that allows an attacker to force an authenticated user to send unintended requests to the target application. In the affected WP Podcasts Manager plugin, the lack of proper CSRF protection means that an attacker who can trick a legitimate user into visiting a crafted URL or submitting a form could trigger the plugin to perform privileged actions. Because the plugin can modify podcast settings and content, a successful attack could alter public data, remove or edit podcast entries, or otherwise disrupt the website’s content.

Affected Systems

Any WordPress site that has installed the Maulik Vora WP Podcasts Manager plugin and has an active version of 1.3 or earlier is at risk. The plugin is distributed under the same vendor name for all versions up to 1.3, with no version‑specific fixes listed in the CNA. No additional platforms or WordPress core versions are specifically mentioned, so all WordPress installations running the plugin are potentially affected.

Risk and Exploitability

The CVSS score of 4.3 places this issue at a medium severity level. The EPSS score of less than 1% indicates that actual exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is most likely a web request made by a victim’s browser; an attacker would need the victim to be logged in and have sufficient privileges for the plugin’s privileged actions. In the absence of proper CSRF tokens, the vulnerability can be exploited remotely with a simple crafted link or form submission. While the known exploitability metrics suggest a low probability of widespread attacks, the potential to modify published content warrants prompt attention.

Generated by OpenCVE AI on April 30, 2026 at 13:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WP Podcasts Manager plugin to a version newer than 1.3, ensuring that CSRF protection is in place.
  • If an update is not yet available, disable or remove the plugin until a properly patched version is released.
  • As a temporary measure, restrict the plugin’s state‑changing endpoints to users with higher capabilities and add custom CSRF token checks to validate incoming requests.

Generated by OpenCVE AI on April 30, 2026 at 13:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-13775 Cross-Site Request Forgery (CSRF) vulnerability in Maulik Vora WP Podcasts Manager allows Cross Site Request Forgery. This issue affects WP Podcasts Manager: from n/a through 1.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Maulik Vora WP Podcasts Manager allows Cross Site Request Forgery. This issue affects WP Podcasts Manager: from n/a through 1.2. Cross-Site Request Forgery (CSRF) vulnerability in Maulik Vora WP Podcasts Manager wp-podcasts-manager allows Cross Site Request Forgery.This issue affects WP Podcasts Manager: from n/a through <= 1.3.
Title WordPress WP Podcasts Manager <= 1.2 - Cross Site Request Forgery (CSRF) Vulnerability WordPress WP Podcasts Manager plugin <= 1.3 - Cross Site Request Forgery (CSRF) vulnerability
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00017}

epss

{'score': 0.0002}


Wed, 07 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 May 2025 14:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Maulik Vora WP Podcasts Manager allows Cross Site Request Forgery. This issue affects WP Podcasts Manager: from n/a through 1.2.
Title WordPress WP Podcasts Manager <= 1.2 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:46.868Z

Reserved: 2025-05-07T10:44:26.561Z

Link: CVE-2025-47597

cve-icon Vulnrichment

Updated: 2025-05-07T17:19:45.830Z

cve-icon NVD

Status : Deferred

Published: 2025-05-07T15:16:13.453

Modified: 2026-04-23T15:30:34.180

Link: CVE-2025-47597

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T13:30:15Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)