PT-2025-39155 · WordPress · Podlove Podcast Publisher

Arkadiusz Hydzik

·

Published

2025-09-23

·

Updated

2025-09-24

·

CVE-2025-10147

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Podlove Podcast Publisher versions up to and including 4.2.6
Description The Podlove Podcast Publisher plugin for WordPress is susceptible to arbitrary file uploads because of a lack of file type validation in the move as original file function. This allows unauthenticated attackers to upload arbitrary files to the affected server, potentially leading to remote code execution.
Recommendations Update Podlove Podcast Publisher to a version newer than 4.2.6.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-10147

Affected Products

Podlove Podcast Publisher