First published: Thu Apr 24 2025(Updated: )
Unrestricted Upload of File with Dangerous Type vulnerability in Angelo Mandato PowerPress Podcasting allows Upload a Web Shell to a Web Server. This issue affects PowerPress Podcasting: from n/a through 11.12.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Angelo Mandato PowerPress Podcasting | <=11.12.5 | |
Blubrry PowerPress Podcasting | <=11.12.5 |
Update the WordPress PowerPress Podcasting wordpress plugin to the latest available version (at least 11.12.6).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-46264 is considered a critical vulnerability due to its potential to allow unrestricted file uploads, leading to web shell exploitation.
To mitigate CVE-2025-46264, upgrade PowerPress Podcasting to version 11.12.6 or later.
CVE-2025-46264 allows the upload of files with dangerous types, potentially including executable scripts.
PowerPress Podcasting versions prior to 11.12.6, specifically from n/a through 11.12.5, are vulnerable to CVE-2025-46264.
The vendor for CVE-2025-46264 is Angelo Mandato, responsible for the PowerPress Podcasting plugin.