CVE-2025-46264: WordPress PowerPress Podcasting <= 11.12.5 - Arbitrary File Upload Vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in Angelo Mandato PowerPress Podcasting allows Upload a Web Shell to a Web Server. This issue affects PowerPress Podcasting: from n/a through 11.12.5.
Other sources
Unrestricted Upload of File with Dangerous Type vulnerability in blubrry PowerPress Podcasting powerpress allows Upload a Web Shell to a Web Server.This issue affects PowerPress Podcasting: from n/a through <= 11.12.5.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46264?
CVE-2025-46264 is considered a critical vulnerability due to its potential to allow unrestricted file uploads, leading to web shell exploitation.
How do I fix CVE-2025-46264?
To mitigate CVE-2025-46264, upgrade PowerPress Podcasting to version 11.12.6 or later.
What types of files are affected by CVE-2025-46264?
CVE-2025-46264 allows the upload of files with dangerous types, potentially including executable scripts.
Which versions of PowerPress Podcasting are vulnerable to CVE-2025-46264?
PowerPress Podcasting versions prior to 11.12.6, specifically from n/a through 11.12.5, are vulnerable to CVE-2025-46264.
Who is the vendor for CVE-2025-46264?
The vendor for CVE-2025-46264 is Angelo Mandato, responsible for the PowerPress Podcasting plugin.