PT-2026-58720 · WordPress · Podlove Podcast Publisher
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Podlove Podcast Publisher versions prior to 4.5.2
Description
Missing file type validation in the
podlove handle cache files() function allows unauthenticated attackers to upload arbitrary files to the server. This flaw in the image cache can lead to remote code execution, where an attacker can execute malicious commands on the affected system.Recommendations
Update Podlove Podcast Publisher to version 4.5.2 or later.
Exploit
Fix
RCE
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Podlove Podcast Publisher