CVE-2025-46264
CVSS 3.1 Score 9.9 of 10 (high)
Details
Summary
CVE-2025-46264 is a file upload vulnerability affecting Angelo Mandato PowerPress Podcasting from versions n/a through 11.12.5. An attacker can exploit this Unrestricted Upload of File with Dangerous Type vulnerability to upload a web shell to a web server, potentially gaining unauthorized access and control. This issue poses a significant risk, as web shells can be used for various malicious activities, including data theft, website defacement, and system compromise. Users are strongly urged to update their PowerPress Podcasting installation as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- PowerPress Podcasting Plugin
Affected Vendors
- WordPress