{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/podlove-podcast-publisher/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-16099"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Podlove Podcast Publisher"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Podlove"],"content_html":"\u003cp\u003eThe Podlove Podcast Publisher plugin for WordPress (versions 4.5.3 and earlier) contains a critical vulnerability due to insufficient file path validation within the 'create_link_item' function. Authenticated users with contributor-level privileges or higher can leverage this flaw to delete arbitrary files on the web server. This capability poses a significant risk to site integrity and availability, as attackers can delete core WordPress configuration files like 'wp-config.php' to force a re-installation or trigger further exploit chains.\u003c/p\u003e\n\u003cp\u003eFurthermore, researchers identified a property-oriented programming (POP) chain within the 'Podlove\\ImageCache\\GenerationGuard' class. An attacker can supply serialized data that, when unserialized, populates the object's properties to invoke 'wp_delete_file()' on a target file of their choosing. This facilitates remote code execution (RCE) scenarios by removing specific application files that redirect execution flow or weaken security postures. Given the plugin's broad utility in podcast hosting, defenders should prioritize patching or disabling the plugin until version 4.5.4 or later is deployed.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the deletion of arbitrary files on the underlying filesystem, provided the web server process has the necessary file system permissions. This can lead to a complete denial of service for the WordPress site, the destruction of critical configuration files, or facilitate RCE through the identified POP chain mechanism. Impacted organizations include any entities running affected versions of the Podlove Podcast Publisher plugin on WordPress infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Podlove Podcast Publisher plugin to version 4.5.4 or later immediately to resolve the path validation flaw.\u003c/li\u003e\n\u003cli\u003eImplement access control reviews to ensure contributor-level accounts are restricted appropriately, minimizing the potential impact of authenticated exploit vectors.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for anomalous POST requests directed at plugin-specific API endpoints that handle file linking or management.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-16T06:24:50Z","date_published":"2026-08-16T06:24:50Z","id":"https://feed.craftedsignal.io/briefs/2026-08-podlove-arbitrary-file-deletion/","summary":"Authenticated attackers can exploit a path traversal vulnerability in the Podlove Podcast Publisher plugin to delete arbitrary system files, potentially achieving remote code execution via POP chain or wp-config.php removal.","title":"Arbitrary File Deletion in Podlove Podcast Publisher Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-08-podlove-arbitrary-file-deletion/"}],"language":"en","title":"CraftedSignal Threat Feed - Podlove Podcast Publisher","version":"https://jsonfeed.org/version/1.1"}