CVE-2025-46264

CVSS 3.1 Score 9.9 of 10 (high)

Details

Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 434

Summary

CVE-2025-46264 is a file upload vulnerability affecting Angelo Mandato PowerPress Podcasting from versions n/a through 11.12.5. An attacker can exploit this Unrestricted Upload of File with Dangerous Type vulnerability to upload a web shell to a web server, potentially gaining unauthorized access and control. This issue poses a significant risk, as web shells can be used for various malicious activities, including data theft, website defacement, and system compromise. Users are strongly urged to update their PowerPress Podcasting installation as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • PowerPress Podcasting Plugin

Affected Vendors

  • WordPress