WordPress Plugin Vulnerabilities
Podlove Podcast Publisher < 4.5.2 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter
Description
The plugin is vulnerable to Arbitrary File Upload due to missing file type validation in the 'podlove_handle_cache_files' function. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affects Plugins
References
Miscellaneous
Original Researcher
Talal Nasraddeen
Verified
No
WPVDB ID
Timeline
Publicly Published
2026-07-14 (about 14 days ago)
Added
2026-07-16 (about 11 days ago)
Last Updated
2026-07-27 (about 49 minutes ago)