Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

CVE-2026-16099: Podlove Podcast Publisher plugin: Arbitrary file deletion on WordPress

CVE-2026-16099 · published 19 days ago
Summary

Authenticated users with contributor-level access can delete any files on the server using the Podlove Podcast Publisher plugin for WordPress. This can lead to serious security risks if the wrong files are deleted, such as the ability to execute malicious code. Update the plugin to the latest version to fix this vulnerability.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
eteubert podlove podcast publisher <= 4.5.3
Original advisory text
Podlove Podcast Publisher <= 4.5.3 - Authenticated (Contributor+) PHP Object Injection to Arbitrary File Deletion via 'unfurl_data' Parameter
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for authenticated attackers, with contributor-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). A viable POP chain exists within the plugin itself via Podlove\ImageCache\GenerationGuard, whose __destruct() method invokes wp_delete_file() with an attacker-controlled file path populated through unserialization.
Severity
8.8 High
CVSS 3.1: 8.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published16 Aug 2026
Updated3 Sep 2026
First seen16 Aug 2026
Sources
CVE-2026-16099 · MITRE
Monitor software like this
Free during beta