What is CVE-2026-16099?
This vulnerability affects the Podlove Podcast Publisher plugin for WordPress in all versions up to and including 4.5.3. It allows authenticated attackers with contributor-level access to perform arbitrary file deletion due to insufficient file path validation in the 'create_link_item' function. Updating the plugin to the latest patched version is strongly recommended.
Azərbaycanca: Bu zəiflik WordPress üçün Podlove Podcast Publisher plaginində aşkarlanıb və 4.5.3 daxil olmaqla bütün versiyalara təsir edir. 'create_link_item' funksiyasındakı qeyri-kafi fayl yolu doğrulaması səbəbindən, Contributor səviyyəli autentifikasiya olunmuş hücumçu ixtiyari fayl silməsi həyata keçirə bilər. Plaginin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of the Podlove Podcast Publisher plugin are affected by CVE-2026-16099?
This vulnerability affects all versions of the Podlove Podcast Publisher plugin for WordPress up to and including 4.5.3.
What level of authentication is required for an attacker to exploit CVE-2026-16099?
An attacker must be authenticated with contributor-level access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.