Arbitrary File Deletion Vulnerability in Podlove Podcast Publisher Plugin for WordPress
CVE-2026-16099
8.8HIGH
What is CVE-2026-16099?
The Podlove Podcast Publisher plugin for WordPress has a vulnerability that allows authenticated users with contributor-level access or higher to delete arbitrary files from the server. This issue arises from insufficient validation of file paths in the create_link_item function across all versions up to 4.5.3. An exploitable path exists within the plugin's code, particularly through the Podlove\ImageCache\GenerationGuard class, enabling malicious actors to invoke wp_delete_file() with a manipulated file path. This could lead to critical system files being deleted, potentially allowing for remote code execution if compromised files such as wp-config.php are affected.
Affected Version(s)
Podlove Podcast Publisher 0 <= 4.5.3