VYPR
Medium severity4.3NVD Advisory· Published May 7, 2025· Updated Apr 23, 2026

CVE-2025-47597

CVE-2025-47597

Description

Cross-Site Request Forgery (CSRF) vulnerability in Maulik Vora WP Podcasts Manager wp-podcasts-manager allows Cross Site Request Forgery.This issue affects WP Podcasts Manager: from n/a through <= 1.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CSRF vulnerability in WP Podcasts Manager plugin (≤1.3) allows attackers to force privileged users to perform unintended actions via crafted requests.

The WP Podcasts Manager plugin for WordPress suffers from a Cross-Site Request Forgery (CSRF) vulnerability in versions up to and including 1.3. The root cause is the absence of CSRF protection on certain administrative actions, enabling an attacker to trick a logged-in administrator into executing unwanted operations without their consent [1].

Exploitation requires user interaction: a privileged user must click a malicious link, visit a crafted page, or submit a specially designed form while authenticated. The attacker does not need any prior authentication or special network access, as the attack can be delivered via email, social engineering, or by embedding the malicious link on a third-party site [1].

Successful exploitation allows the attacker to force the victim to perform actions under their current session, such as modifying plugin settings, deleting podcast episodes, or altering configuration. This could lead to unauthorized changes or data loss, though the impact is limited to actions the victim user is permitted to perform [1].

The vulnerability has been addressed in version 1.4 of the plugin. Users are strongly advised to update immediately. Patchstack users can enable auto-updates for vulnerable plugins. While the CVSS score is 4.3 (Medium), such CSRF flaws are frequently targeted in mass-exploit campaigns against WordPress sites [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.