Deserialization of Untrusted Data vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress.This issue affects Podlove Podcast Publisher: from n/a through <= 4.1.15.
The vulnerability stems from unsafe processing (deserialization) of input data without proper verification of its origin and content (CWE-94, CWE-82). An attacker with administrator privileges can submit a specially crafted malicious object, which during server-side deserialization leads to execution of arbitrary PHP code. This mechanism allows escaping the application context and affecting the host system resources.
Successful exploitation of the vulnerability allows an attacker to remotely execute arbitrary code on the server (RCE), and consequently to gain full control over the environment — including access to sensitive data, file modification, and potential lateral movement in the infrastructure.
The Podlove Podcast Publisher plugin should be immediately updated to a version higher than 4.1.15. Patches are available in the WordPress repository and from the vendor according to references (Patchstack). Additionally, it is recommended to apply the principle of least privilege and monitor the activity of administrator accounts.
The Podlove Podcast Publisher plugin (podlove-podcasting-plugin-for-wordpress) in versions from the beginning through 4.1.15 inclusive, running on the WordPress platform.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HPodlove Podcast Publisher
APPPodlove≤ 4.1.15
Related vulnerabilities
CSRF umożliwiający zdalne wykonanie kodu w Podlove Podcast Publisher
SQL Injection w module 'Social & Donations' wtyczki Podlove Podcast Publisher
SQL injection w Podlove Podcast Publisher dla WordPress via CSRF
Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Pu...
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Podlove ...