Arbitrary File Upload Vulnerability in PowerPress Podcasting by Angelo Mandato
CVE-2025-46264

9.9CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 April 2025

What is CVE-2025-46264?

An Arbitrary File Upload vulnerability exists in the PowerPress Podcasting plugin by Angelo Mandato, which allows authenticated users to upload files of potentially dangerous types. This raises significant security concerns, as it can lead to unauthorized web shell uploads to the web server, ultimately exposing sensitive data and compromising the integrity of the system. The vulnerability affects versions of PowerPress Podcasting from n/a through 11.12.5, making it crucial for users to apply necessary updates and implement security measures.

Affected Version(s)

PowerPress Podcasting 0 <= 11.12.5

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Trương Hữu Phúc (truonghuuphuc) (Patchstack Alliance)
.