๐Ÿ” CVE Alert

CVE-2026-16099

HIGH 8.8

Podlove Podcast Publisher <= 4.5.3 - Authenticated (Contributor+) PHP Object Injection to Arbitrary File Deletion via 'unfurl_data' Parameter

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for authenticated attackers, with contributor-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). A viable POP chain exists within the plugin itself via Podlove\ImageCache\GenerationGuard, whose __destruct() method invokes wp_delete_file() with an attacker-controlled file path populated through unserialization.

CWE CWE-502
Vendor eteubert
Product podlove podcast publisher
Published Aug 16, 2026
Stay Ahead of the Next One

Get instant alerts for eteubert podlove podcast publisher

Be the first to know when new high vulnerabilities affecting eteubert podlove podcast publisher are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

eteubert / Podlove Podcast Publisher
0 โ‰ค 4.5.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/3aa6fd71-337f-4998-a15d-650aa4f6142c?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/podlove-podcasting-plugin-for-wordpress/tags/4.5.3/lib/modules/shownotes/rest_api.php#L585 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/podlove-podcasting-plugin-for-wordpress/tags/4.5.3/lib/model/base.php#L552 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/podlove-podcasting-plugin-for-wordpress/tags/4.5.3/lib/image_cache/generation_guard.php#L19 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/podlove-podcasting-plugin-for-wordpress/tags/4.5.3/lib/image_cache/generation_guard.php#L57 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/podlove-podcasting-plugin-for-wordpress/tags/4.5.3/lib/modules/shownotes/rest_api.php#L538 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/podlove-podcasting-plugin-for-wordpress/tags/4.5.3/lib/modules/shownotes/rest_api.php#L630 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?reponame=&old=3648110%40podlove-podcasting-plugin-for-wordpress&new=3648110%40podlove-podcasting-plugin-for-wordpress

Credits

Wordfence PRISM