CyberRota Analysis
AI-GeneratedThe Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to inadequate file path validation, affecting all versions up to 4.5.3. Authenticated attackers with contributor-level access can exploit this vulnerability to delete critical files, potentially leading to remote code execution. WordPress site administrators using this plugin should prioritize patching to mitigate the risk of unauthorized file manipulation and system compromise.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for authenticated attackers, with contributor-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). A viable POP chain exists within the plugin itself via Podlove\ImageCache\GenerationGuard, whose __destruct() method invokes wp_delete_file() with an attacker-controlled file path populated through unserialization.