The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for authenticated attackers, with contributor-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). A viable POP chain exists within the plugin itself via Podlove\ImageCache\GenerationGuard, whose __destruct() method invokes wp_delete_file() with an attacker-controlled file path populated through unserialization.
We have discovered 1,595 live websites that are affected by CVE-2026-16099.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,595 live websites (100% of Podlove Podcasting Plugin For Wordpress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 46 versions ( 100% of all versions) |
| 170 websites | |
| 1,183 websites | |
| 32 websites | |
| 32 websites | |
| 32 websites | |
| 21 websites | |
| 16 websites | |
| 14 websites | |
| 13 websites | |
| 10 websites |
| .de | 876 websites |
| .com | 229 websites |
| .org | 79 websites |
| .net | 69 websites |
| .eu | 34 websites |
| .at | 29 websites |
| .ch | 24 websites |
| .info | 23 websites |
| .nl | 22 websites |
| .fr | 14 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****************.de | **,*** | ||
| *****.*********.net | ***,*** | ||
| ***.io | ***,*** | ||
| *****************.org | ***,*** | ||
| *********.es | ***,*** | ||
| ************.de | ***,*** | ||
| ********.com | ***,*** | ||
| **************************.de | ***,*** | ||
| ***.de | ***,*** | ||
| ******.*********.net | ***,*** |
FAQ