CVE-2026-13001

Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all versions up to, and including, 4.5.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.


We have discovered 1,622 live websites that are affected by CVE-2026-13001.

Run a Free Instant Scan




Affected Software

Product  Podlove Podcasting Plugin For Wordpress
Category Wordpress Plugins
Vulnerable Domains1,622 live websites (100% of Podlove Podcasting Plugin For Wordpress install base)
Vulnerable Versions
  • from 0 through 4.5.1
Vulnerable Versions Count46 versions ( 98% of all versions)


Common Weakness Enumeration

CWE-20 Improper Input Validation



Details

  • Published - Jul 14, 2026
  • Updated - Jul 14, 2026

Credits

  • Talal Nasraddeen (finder)

Website Distribution by Country

Number of websites using CVE-2026-13001
United States180 websites



Germany1,190 websites
France36 websites
Switzerland34 websites
Austria32 websites
Netherlands21 websites
Denmark16 websites
Spain14 websites
GB12 websites
Italy11 websites

Website Distribution by TLD

Number of websites using CVE-2026-13001
.de876 websites
.com238 websites
.org87 websites
.net72 websites
.eu34 websites
.at29 websites
.ch26 websites
.info23 websites
.nl22 websites
.fr17 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-13001

Top websites that are affected by CVE-2026-13001. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****************.de Germany**,***
*****.*********.net United States***,***
***.io United States***,***
***.de Germany***,***
************.com Germany***,***
*****************.org United States***,***
***********.com United States***,***
*********.es Germany***,***
************.de Germany***,***
********.com France***,***
See full domain list

FAQ

CVE-2026-13001 is Improper Input Validation in Podlove Podcasting Plugin For Wordpress
A total of 1,622 websites have been identified as vulnerable to CVE-2026-13001, based on global website indexing conducted by WebTechSurvey.
The Podlove Podcasting Plugin For Wordpress is affected by the CVE-2026-13001 vulnerability.
Podlove Podcasting Plugin For Wordpress versions up to and including 4.5.1 are vulnerable to CVE-2026-13001.