Impact
The vulnerability resides in the Podlove Podcast Publisher WordPress plugin and allows an attacker who does not need any user credentials to upload files to the server by manipulating the podlove_image_cache_url parameter. Because the plugin does not perform file‑type validation in its podlove_handle_cache_files routine, the attacker can upload executable scripts or other malicious files that the web server would later execute, thereby enabling remote code execution. This issue corresponds to CWE‑20, an input validation deficiency.
Affected Systems
The flaw affects the Podlove Podcast Publisher plugin for WordPress, developed by eteubert. All releases up to and including 4.5.1 are impacted. Users running any of those versions on a WordPress installation are at risk.
Risk and Exploitability
The CVSS score is 9.8, reflecting a critical danger to confidentiality, integrity, and availability. The EPSS score of 0.00828 (≈0.8%) indicates that, although the flaw is severe, the likelihood of exploitation at this time is still modest. It is not listed in the CISA KEV catalog. The attack requires only an unauthenticated HTTP request to the plugin’s cache handling endpoint, making it readily exploitable by any actor with network access to the site.
OpenCVE Enrichment