CVE-2026-13001
Deferred Deferred - Pending Action

Arbitrary File Upload in Podlove Podcast Publisher WordPress Plugin

Vulnerability report for CVE-2026-13001, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-14

Assigner: Wordfence

Description

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all versions up to, and including, 4.5.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-14
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
podlove podlove_podcast_publisher to 4.5.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Podlove Podcast Publisher WordPress plugin allows unauthenticated attackers to upload arbitrary files to the server due to missing file type validation in the image cache function. Attackers can exploit this by using specially crafted URLs to bypass validation and upload executable files like PHP scripts, potentially leading to remote code execution.

Detection Guidance

Check WordPress installations for the Podlove Podcast Publisher plugin versions up to 4.5.1. Look for unexpected files in cache directories, particularly those with PHP extensions or unusual image formats. Review server logs for upload attempts from unauthenticated sources.

Impact Analysis

This vulnerability can allow attackers to upload malicious files to your server, which may lead to remote code execution. This could result in complete control over your WordPress site, data theft, or further attacks on your server or network. Unauthorized file uploads can compromise site integrity and confidentiality.

Compliance Impact

This vulnerability can lead to unauthorized access and data breaches, which may violate GDPR's data protection requirements or HIPAA's security rules for protected health information. Non-compliance could result in legal penalties, fines, or reputational damage due to compromised sensitive data.

Mitigation Strategies
  • Update the Podlove Podcast Publisher plugin to the latest version immediately to apply the security fixes.
  • Remove any suspicious files from the server, especially those in cache directories that do not match standard image formats.
  • Flush the plugin's cache to remove potentially malicious cached files as part of the update process.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13001. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart