CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-52393

CVSS 9.1v3.1pub. 2024-11-14upd. 2026-04-23

Deserialization of Untrusted Data vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress.This issue affects Podlove Podcast Publisher: from n/a through <= 4.1.15.

🤖 AI Analysis
How it works

The vulnerability stems from unsafe processing (deserialization) of input data without proper verification of its origin and content (CWE-94, CWE-82). An attacker with administrator privileges can submit a specially crafted malicious object, which during server-side deserialization leads to execution of arbitrary PHP code. This mechanism allows escaping the application context and affecting the host system resources.

Impact

Successful exploitation of the vulnerability allows an attacker to remotely execute arbitrary code on the server (RCE), and consequently to gain full control over the environment — including access to sensitive data, file modification, and potential lateral movement in the infrastructure.

Mitigation & patch

The Podlove Podcast Publisher plugin should be immediately updated to a version higher than 4.1.15. Patches are available in the WordPress repository and from the vendor according to references (Patchstack). Additionally, it is recommended to apply the principle of least privilege and monitor the activity of administrator accounts.

Who is affected

The Podlove Podcast Publisher plugin (podlove-podcasting-plugin-for-wordpress) in versions from the beginning through 4.1.15 inclusive, running on the WordPress platform.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Podlove Podcast Publisher

    APP
    Podlove
    ≤ 4.1.15
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Deserialization
CWE
References

Related vulnerabilities

CVE-2024-43984CRITICAL9.6PL ✓same product

CSRF umożliwiający zdalne wykonanie kodu w Podlove Podcast Publisher

CVE-2021-24666CRITICAL9.8PL ✓same product

SQL Injection w module 'Social & Donations' wtyczki Podlove Podcast Publisher

CVE-2016-10942CRITICAL9.8PL ✓same product

SQL injection w Podlove Podcast Publisher dla WordPress via CSRF

CVE-2024-32712HIGH7.5same product

Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Pu...

CVE-2024-32139HIGH8.5same product

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Podlove ...