CVE-2026-16099

Podlove Podcast Publisher <= 4.5.3 - Authenticated (Contributor+) PHP Object Injection to Arbitrary File Deletion via 'unfurl_data' Parameter

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for authenticated attackers, with contributor-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). A viable POP chain exists within the plugin itself via Podlove\ImageCache\GenerationGuard, whose __destruct() method invokes wp_delete_file() with an attacker-controlled file path populated through unserialization.


We have discovered 1,595 live websites that are affected by CVE-2026-16099.

Run a Free Instant Scan




Affected Software

Product  Podlove Podcasting Plugin For Wordpress
Category Wordpress Plugins
Vulnerable Domains1,595 live websites (100% of Podlove Podcasting Plugin For Wordpress install base)
Vulnerable Versions
  • from 0 through 4.5.3
Vulnerable Versions Count46 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-502 Deserialization of Untrusted Data



Details

  • Published - Aug 16, 2026
  • Updated - Aug 17, 2026

Credits

  • Wordfence PRISM (finder)

Website Distribution by Country

Number of websites using CVE-2026-16099
United States170 websites



Germany1,183 websites
Austria32 websites
Switzerland32 websites
France32 websites
Netherlands21 websites
Denmark16 websites
Spain14 websites
GB13 websites
Italy10 websites

Website Distribution by TLD

Number of websites using CVE-2026-16099
.de876 websites
.com229 websites
.org79 websites
.net69 websites
.eu34 websites
.at29 websites
.ch24 websites
.info23 websites
.nl22 websites
.fr14 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-16099

Top websites that are affected by CVE-2026-16099. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****************.de Germany**,***
*****.*********.net United States***,***
***.io United States***,***
*****************.org United States***,***
*********.es Germany***,***
************.de Germany***,***
********.com France***,***
**************************.de Germany***,***
***.de Germany***,***
******.*********.net Germany***,***
See full domain list

FAQ

CVE-2026-16099 is Deserialization of Untrusted Data in Podlove Podcasting Plugin For Wordpress
A total of 1,595 websites have been identified as vulnerable to CVE-2026-16099, based on global website indexing conducted by WebTechSurvey.
The Podlove Podcasting Plugin For Wordpress is affected by the CVE-2026-16099 vulnerability.
Podlove Podcasting Plugin For Wordpress versions up to and including 4.5.3 are vulnerable to CVE-2026-16099.

References