As the page breathed, it spit PHP – Podlove exploit

“How the Podlove exploit hit us and what we did about it”

How a Podlove exploit temporarily paralyzed my site – and how I tamed it

As the operator of several WordPress sites and Podlove instances, you have certain rituals: regular backups, updates, and the stoic certainty that technology usually fits in — until it doesn’t. At the end of September 2025, this certainty was confirmed by a highly critical vulnerability in Podlove Podcast Publisher Abruptly disturbed (CVE-2025-10147). What initially turned out to be ‘funny behaviour’ of the media files turned out to be a targeted exploitation of a missing file type validation: Attackers could use the image cache function to send arbitrary files, including PHP scripts, to the server. NVD+1

Continue reading ‘When the page breathed, it spit PHP – Podlove exploit’