WordPress Podlove Podcast Publisher是WordPress基金会的一款播客发布插件。 WordPress Podlove Podcast Publisher 4.5.1及之前版本存在输入验证错误漏洞,该漏洞源于在'podlove_handle_cache_files'函数中缺少文件类型验证,可能导致未经身份验证的攻击者上传任意文件,从而实现远程代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| eteubert | Podlove Podcast Publisher | ≤ 4.5.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| eteubert | Podlove Podcast Publisher | 0 ~ 4.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Podlove Podcast Publisher plugin for WordPress through 4.5.1 is vulnerable to arbitrary file uploads due to missing file type validation in the podlove_handle_cache_files function. The image cache derives the stored file extension from the path of the attacker supplied source URL, while the image validation is performed against a different file name taken from the full source URL, so a source URL whose path carries a dangerous extension is written to the cache with that extension. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-13001.yaml | POC Details |
No comments yet