S4E just found a high claris filemaker server panel detection scanner
critical·Product Based Web Vulnerabilities·Updated Aug 30, 2026

CVE-2026-13001 Scanner

CVE-2026-13001 Scanner - Arbitrary File Upload vulnerability in Podlove Podcast Publisher

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.6k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-13001
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all versions up to, and including, 4.5.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Podlove Podcast Publisherby eteubert
0
Updated Aug 22, 2026View on NVD →
Detail

Podlove Podcast Publisher is a popular plugin for WordPress, used by podcasters to publish and manage podcasts on their sites. Developed by Podlove, this plugin is integrated within WordPress environments, providing tools to streamline podcast publication workflows. It allows users to enhance their WordPress sites with customizable podcast feeds, incorporate analytics, and manage subscriptions. Podlove's plugin is widely used across various podcasting platforms to ensure efficient content delivery and audience engagement. The plugin plays a significant role in the distribution and logistics of podcast content around the internet, supporting diverse operational needs.

The vulnerability present in Podlove Podcast Publisher versions up to 4.5.1 involves an arbitrary file upload issue. Due to missing file type validation in the `podlove_handle_cache_files` function, malicious files could potentially be uploaded. This exposes WordPress sites to external attacks, as dangerous files might be written into web-accessible directories. Without proper input validation, attackers can exploit this vulnerability to bypass security mechanisms, posing severe risks to site integrity.

The vulnerability arises from the lack of stringent validation of file types during the caching process within the Podlove Podcast Publisher. The application determines the file extension from a potentially malicious source URL, permitting harmful files to reside on the web server. The source URL path carries extensions that may not match trusted types, allowing attackers to upload executable scripts. Such an oversight in validation between source files and cached files facilitates security breaches.

If exploited, this vulnerability can let unauthenticated attackers upload arbitrary files with risky extensions to the server. Malicious parties could execute code remotely, leading to unauthorized access and full compromise of the WordPress site. The capability to upload harmful scripts can result in server hijacking, data leaks, and can be further exploited for defacing the website or distributing malware.

REFERENCES

Solution Advice
  • Update Podlove Podcast Publisher to version 4.5.2 or later.
  • Implement strict file validation checks server-side to prevent unauthorized file extensions.
  • Regularly audit and monitor web server directories for unauthorized file submissions.
  • Ensure server permissions are correctly configured to restrict unauthorized file execution.
  • Utilize web application firewalls to capture and block malicious upload attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.