PT-2026-58720 · WordPress · Podlove Podcast Publisher

·

CVE-2026-13001

·

Published

2026-07-14

·

Updated

2026-07-17

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Podlove Podcast Publisher versions prior to 4.5.2
Description Missing file type validation in the podlove handle cache files() function allows unauthenticated attackers to upload arbitrary files to the server. This flaw in the image cache can lead to remote code execution, where an attacker can execute malicious commands on the affected system.
Recommendations Update Podlove Podcast Publisher to version 4.5.2 or later.

Exploit

Fix

RCE

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13001

Affected Products

Podlove Podcast Publisher