WordPress Plugin Vulnerabilities

Podlove Podcast Publisher < 4.5.2 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter

Description

The plugin is vulnerable to Arbitrary File Upload due to missing file type validation in the 'podlove_handle_cache_files' function. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

Affects Plugins

References

Miscellaneous

Original Researcher
Talal Nasraddeen
Verified
No

Timeline

Publicly Published
2026-07-14 (about 14 days ago)
Added
2026-07-16 (about 11 days ago)
Last Updated
2026-07-27 (about 49 minutes ago)

Other