漏洞描述
Podlove Podcast Publisher plugin for WordPress through 4.5.1 is vulnerable to arbitrary file uploads due to missing file type validation in the podlove_handle_cache_files function. The image cache derives the stored file extension from the path of the attacker supplied source URL, while the image validation is performed against a different file name taken from the full source URL, so a source URL whose path carries a dangerous extension is written to the cache with that extension.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/podlove/podlove-publisher/commit/5b32468601e903bae2bcacfaf36ff583d2bc9387↗www.wordfence.comhttps://www.wordfence.com/threat-intel/vulnerabilities/id/f81a3429-f378-4295-adbe-ad6f1df59701?source=cve↗github.comhttps://github.com/advisories/GHSA-7gcx-p8g5-3g9x↗plugins.trac.wordpress.orghttps://plugins.trac.wordpress.org/changeset/3597461/podlove-podcasting-plugin-for-wordpress↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-13001↗