The Podlove Podcast Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.2. This is due to missing or incorrect nonce validation on the ajax_transcript_delete() function. This makes it possible for unauthenticated attackers to delete arbitrary episode transcripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
We have discovered 2,358 live websites that are affected by CVE-2025-1383.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 2,358 live websites (89.83% of Podlove Podcasting Plugin For Wordpress install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 105 versions ( 99.06% of all versions) |
![]() | 281 websites |
![]() | 1,702 websites |
![]() | 47 websites |
![]() | 45 websites |
![]() | 37 websites |
![]() | 30 websites |
![]() | 23 websites |
![]() | 21 websites |
![]() | 14 websites |
.de | 1,237 websites |
.com | 423 websites |
.org | 120 websites |
.net | 96 websites |
.eu | 46 websites |
.at | 43 websites |
.ch | 30 websites |
.info | 30 websites |
.nl | 19 websites |
.co.uk | 18 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****************.de | ![]() | **,*** | |
*******.de | ![]() | ***,*** | |
***.de | ![]() | ***,*** | |
***********.com | ![]() | ***,*** | |
*****************.com | ![]() | ***,*** | |
**************************.de | ![]() | ***,*** | |
***.de | ![]() | ***,*** | |
*******.de | ![]() | ***,*** | |
************.com | ![]() | ***,*** | |
*******.de | ![]() | ***,*** |
FAQ