Podlove Podcast Publisher Arbitrary File Upload Vulnerability Allowing Remote Code Execution

Vulnerability

A vulnerability in the Podlove Podcast Publisher plugin for WordPress, present in all versions prior to 4.5.1, allows for arbitrary file uploads. This issue arises from inadequate file type validation in the 'podlove_handle_cache_files' function. As a result, unauthenticated attackers can upload arbitrary files to the server, potentially leading to remote code execution.

Impact

Exploitation of this vulnerability could result in unauthorized file uploads, with the potential for remote code execution on the affected server.

Reproduction

The vulnerability can be reproduced by uploading a file through the 'podlove_image_cache_url' parameter, using a crafted URL that exploits the lack of proper file type validation. The uploaded file can be a PHP script disguised as an image, which, once processed by the server, could execute arbitrary commands.

Remediation

Users are advised to update the Podlove Podcast Publisher plugin to version 4.5.2 or later.

Added: Jul 15, 2026, 5:53 AM
Updated: Jul 15, 2026, 5:53 AM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
0.6
exploitability
9.3
remediation
7.7
relevance
9.2
threat
4.8
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.