Seriously Simple Podcasting <= 3.14.2 - Missing Authorization
medium
The Seriously Simple Podcasting plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.14.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.14.2
- Fixed in:
- 3.14.3
- Disclosed:
- Mar 26, 2026
CVE-2026-39505 on NVD →
Seriously Simple Podcasting [seriously-simple-podcasting] <= 3.14.1 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Stored XSS.This issue affects Seriously Simple Podcasting: from n/a through <= 3.14.1.
- Affected:
- up to 3.14.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 3, 2026
CVE-2026-24952 on NVD →
Seriously Simple Podcasting [seriously-simple-podcasting] <= 3.14.1 (unfixed)
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Server Side Request Forgery.This issue affects Seriously Simple Podcasting: from n/a through <= 3.14.1.
- Affected:
- up to 3.14.1
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2026
CVE-2026-24360 on NVD →
Seriously Simple Podcasting <= 3.14.1 - Authenticated (Editor+) Server-Side Request Forgery
medium
The Seriously Simple Podcasting plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.14.1. This makes it possible for authenticated attackers, with Editor-level access and above, to make web requests to arbitrary locations originating from the web application which c...
- CVSS:
- 5.5
- Affected:
- up to 3.14.1
- Fixed in:
- 3.14.2
- Disclosed:
- Jan 13, 2026
CVE-2026-24360 on NVD →
Seriously Simple Podcasting <= 3.14.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Seriously Simple Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.14.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scri...
- CVSS:
- 6.4
- Affected:
- up to 3.14.1
- Fixed in:
- 3.14.2
- Disclosed:
- Dec 21, 2025
CVE-2026-24952 on NVD →
Seriously Simple Podcasting [seriously-simple-podcasting] <= 3.13.0 (unfixed)
unknown
[en] Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.
- Affected:
- up to 3.13.0
- Fix:
- No patched version reported
- Disclosed:
- Nov 21, 2025
CVE-2025-66060 on NVD →
Seriously Simple Podcasting [seriously-simple-podcasting] <= 3.13.0 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Cross Site Request Forgery.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.
- Affected:
- up to 3.13.0
- Fix:
- No patched version reported
- Disclosed:
- Nov 21, 2025
CVE-2025-66061 on NVD →
Seriously Simple Podcasting [seriously-simple-podcasting] <= 3.13.0 (unfixed)
unknown
[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Retrieve Embedded Sensitive Data.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.
- Affected:
- up to 3.13.0
- Fix:
- No patched version reported
- Disclosed:
- Nov 21, 2025
CVE-2025-66059 on NVD →
Seriously Simple Podcasting <= 3.13.0 - Cross-Site Request Forgery
medium
The Seriously Simple Podcasting plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.13.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick...
- CVSS:
- 4.3
- Affected:
- up to 3.13.0
- Fixed in:
- 3.14.0
- Disclosed:
- Nov 11, 2025
CVE-2025-66061 on NVD →
Seriously Simple Podcasting <= 3.13.0 - Missing Authorization
medium
The Seriously Simple Podcasting plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.13.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.13.0
- Fixed in:
- 3.14.0
- Disclosed:
- Nov 9, 2025
CVE-2025-66060 on NVD →
Seriously Simple Podcasting <= 3.13.0 - Unauthenticated Information Exposure
medium
The Seriously Simple Podcasting plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.13.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 3.13.0
- Fixed in:
- 3.14.0
- Disclosed:
- Nov 9, 2025
CVE-2025-66059 on NVD →
Seriously Simple Podcasting [seriously-simple-podcasting] <= 3.13.0 (unfixed)
unknown
[en] Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.
- Affected:
- up to 3.13.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 27, 2025
CVE-2025-62882 on NVD →
Seriously Simple Podcasting [seriously-simple-podcasting] <= 3.11.1 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows DOM-Based XSS.This issue affects Seriously Simple Podcasting: from n/a through <= 3.11.1.
- Affected:
- up to 3.11.1
- Fix:
- No patched version reported
- Disclosed:
- Oct 22, 2025
CVE-2025-49923 on NVD →
Seriously Simple Podcasting <= 3.11.1 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The Seriously Simple Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts i...
- CVSS:
- 4.4
- Affected:
- up to 3.11.1
- Fixed in:
- 3.12.0
- Disclosed:
- Aug 5, 2025
CVE-2025-49923 on NVD →
Seriously Simple Podcasting <= 3.13.0 - Missing Authorization
medium
The Seriously Simple Podcasting plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.13.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 3.13.0
- Fixed in:
- 3.14.0
- Disclosed:
- Jun 12, 2025
CVE-2025-62882 on NVD →
Seriously Simple Podcasting [seriously-simple-podcasting] < 3.10.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting allows Stored XSS. This issue affects Seriously Simple Podcasting: from n/a through 3.9.0.
- Affected:
- up to 3.10.0
- Fixed in:
- 3.10.0
- Disclosed:
- Apr 24, 2025
CVE-2025-46261 on NVD →
Seriously Simple Podcasting <= 3.9.0 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The Seriously Simple Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inj...
- CVSS:
- 4.4
- Affected:
- up to 3.9.0
- Fixed in:
- 3.10.0
- Disclosed:
- Apr 22, 2025
CVE-2025-46261 on NVD →
Seriously Simple Podcasting [seriously-simple-podcasting] < 3.6.0
unknown
[en] The Seriously Simple Podcasting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.5.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...
- Affected:
- up to 3.6.0
- Fixed in:
- 3.6.0
- Disclosed:
- Nov 5, 2024
CVE-2024-9667 on NVD →
Seriously Simple Podcasting <= 3.5.0 - Reflected Cross-Site Scripting via add_query_arg Parameter
medium
The Seriously Simple Podcasting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.5.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...
- CVSS:
- 6.1
- Affected:
- up to 3.5.0
- Fixed in:
- 3.6.0
- Disclosed:
- Nov 4, 2024
CVE-2024-9667 on NVD →
Seriously Simple Podcasting [seriously-simple-podcasting] < 3.3.0
unknown
[en] The Seriously Simple Podcasting WordPress plugin before 3.3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 3.3.0
- Fixed in:
- 3.3.0
- Disclosed:
- Jul 13, 2024
CVE-2024-3751 on NVD →
Seriously Simple Podcasting <= 3.2.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Seriously Simple Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,...
- CVSS:
- 4.4
- Affected:
- up to 3.2.0
- Fixed in:
- 3.3.0
- Disclosed:
- Jun 22, 2024
CVE-2024-3751 on NVD →
Seriously Simple Podcasting [seriously-simple-podcasting] < 3.1.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Castos Seriously Simple Podcasting allows Reflected XSS.This issue affects Seriously Simple Podcasting: from n/a through 3.0.2.
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.0
- Disclosed:
- Mar 28, 2024
CVE-2024-25599 on NVD →
Seriously Simple Podcasting <= 3.0.2 - Reflected Cross-Site Scripting
medium
The Seriously Simple Podcasting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...
- CVSS:
- 6.1
- Affected:
- up to 3.0.2
- Fixed in:
- 3.1.0
- Disclosed:
- Mar 26, 2024
CVE-2024-25599 on NVD →
Seriously Simple Podcasting [seriously-simple-podcasting] < 3.0.0
unknown
[en] The Seriously Simple Podcasting WordPress plugin before 3.0.0 discloses the Podcast owner's email address (which by default is the admin email address) via an unauthenticated crafted request.
- Affected:
- up to 3.0.0
- Fixed in:
- 3.0.0
- Disclosed:
- Mar 11, 2024
CVE-2023-6444 on NVD →
Seriously Simple Podcasting <= 2.25.3 - Unauthenticated Email Disclosure
medium
The Seriously Simple Podcasting plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.25.3 via the source code. This makes it possible for unauthenticated attackers to extract product owner emails, which can be an administrators.
- CVSS:
- 5.3
- Affected:
- up to 2.25.3
- Fixed in:
- 3.0.0
- Disclosed:
- Feb 17, 2024
CVE-2023-6444 on NVD →
Seriously Simple Podcasting [seriously-simple-podcasting] < 2.19.1
unknown
[en] The Seriously Simple Podcasting WordPress plugin before 2.19.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege u...
- Affected:
- up to 2.19.1
- Fixed in:
- 2.19.1
- Disclosed:
- Jan 16, 2023
CVE-2022-4571 on NVD →
Seriously Simple Podcasting <= 2.19.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
medium
The Seriously Simple Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 2.19.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject...
- CVSS:
- 6.4
- Affected:
- up to 2.19.0
- Fixed in:
- 2.19.1
- Disclosed:
- Dec 21, 2022
CVE-2022-4571 on NVD →
Seriously Simple Podcasting <= 2.16.0 - Cross-Site Request Forgery
high
The Seriously Simple Podcasting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.16.0. This is due to missing or incorrect nonce validation on the save_step function as well as other functions related to onboarding. This makes it possible for unauthenticated attackers...
- CVSS:
- 8.8
- Affected:
- up to 2.16.0
- Fixed in:
- 2.16.1
- Disclosed:
- Sep 23, 2022
CVE-2022-40132 on NVD →
Seriously Simple Podcasting [seriously-simple-podcasting] < 2.16.1
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Seriously Simple Podcasting plugin <= 2.16.0 at WordPress, leading to plugin settings change.
- Affected:
- up to 2.16.1
- Fixed in:
- 2.16.1
- Disclosed:
- Sep 23, 2022
CVE-2022-40132 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database