Vendor
high
advisory
Arbitrary File Deletion in Podlove Podcast Publisher Plugin for WordPress
1 TTP 1 CVEAuthenticated attackers can exploit a path traversal vulnerability in the Podlove Podcast Publisher plugin to delete arbitrary system files, potentially achieving remote code execution via POP chain or wp-config.php removal.
Podlove Podcast Publisher
1t
1c
critical
advisory
Critical Vulnerability in Podlove Podcast Publisher Plugin Allows Unauthenticated File Uploads Leading to RCE
1 rule 3 TTPs 1 CVE 4 IOCsA critical vulnerability, CVE-2026-13001, in the Podlove Podcast Publisher plugin for WordPress, impacting versions up to and including 4.5.1, allows unauthenticated attackers to upload arbitrary files due to missing file type validation, potentially leading to remote code execution on the server.
PoC
Podlove Podcast Publisher <= 4.5.1
wordpress
plugin
vulnerability
file-upload
rce
1r
3t
1c
4i
updated