CVE-2026-13001: Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlovehandlecachefiles' function in all versions up to, and including, 4.5.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Podlove Podcast Publisher (WordPress plugin)to a version that resolves this vulnerability.Fixed in 4.5.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13001?
CVE-2026-13001 has a critical severity rating of 9.8.
What does CVE-2026-13001 allow attackers to do?
CVE-2026-13001 allows unauthenticated attackers to upload arbitrary files due to lack of file type validation.
How can I mitigate CVE-2026-13001?
To mitigate CVE-2026-13001, update the Podlove Podcast Publisher plugin to version 4.5.2 or later.
Which versions of Podlove Podcast Publisher are affected by CVE-2026-13001?
CVE-2026-13001 affects all versions of Podlove Podcast Publisher up to and including version 4.5.1.
What kind of vulnerability is described in CVE-2026-13001?
CVE-2026-13001 is classified as an Input Validation vulnerability.