Critical Vulnerability in Podlove Podcast Publisher Plugin for WordPress: CVE-2026-16099
The Podlove Podcast Publisher plugin for WordPress, versions up to and including 4.5.3, is vulnerable to arbitrary file deletion due to insufficient file path validation. This allows authenticated attackers with contributor-level access to delete arbitrary files, potentially leading to remote code execution. The vulnerability has a CVSS score of 8.8 and is classified as CWE-502 Deserialization. Immediate patching is recommended.