plugin

Seriously Simple Podcasting Vulnerabilities

29 known security issues reported for the Seriously Simple Podcasting WordPress plugin. Most recent disclosed Mar 26, 2026.

1 high 14 medium

Running Seriously Simple Podcasting on your site? Check whether your installed version is affected.

Scan your site free

Seriously Simple Podcasting <= 3.14.2 - Missing Authorization

medium

The Seriously Simple Podcasting plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.14.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.14.2
Fixed in:
3.14.3
Disclosed:
Mar 26, 2026

CVE-2026-39505 on NVD →

Seriously Simple Podcasting [seriously-simple-podcasting] <= 3.14.1 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Stored XSS.This issue affects Seriously Simple Podcasting: from n/a through <= 3.14.1.

Affected:
up to 3.14.1
Fix:
No patched version reported
Disclosed:
Feb 3, 2026

CVE-2026-24952 on NVD →

Seriously Simple Podcasting [seriously-simple-podcasting] <= 3.14.1 (unfixed)

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Server Side Request Forgery.This issue affects Seriously Simple Podcasting: from n/a through <= 3.14.1.

Affected:
up to 3.14.1
Fix:
No patched version reported
Disclosed:
Jan 22, 2026

CVE-2026-24360 on NVD →

Seriously Simple Podcasting <= 3.14.1 - Authenticated (Editor+) Server-Side Request Forgery

medium

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.14.1. This makes it possible for authenticated attackers, with Editor-level access and above, to make web requests to arbitrary locations originating from the web application which c...

CVSS:
5.5
Affected:
up to 3.14.1
Fixed in:
3.14.2
Disclosed:
Jan 13, 2026

CVE-2026-24360 on NVD →

Seriously Simple Podcasting <= 3.14.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.14.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scri...

CVSS:
6.4
Affected:
up to 3.14.1
Fixed in:
3.14.2
Disclosed:
Dec 21, 2025

CVE-2026-24952 on NVD →

Seriously Simple Podcasting [seriously-simple-podcasting] <= 3.13.0 (unfixed)

unknown

[en] Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.

Affected:
up to 3.13.0
Fix:
No patched version reported
Disclosed:
Nov 21, 2025

CVE-2025-66060 on NVD →

Seriously Simple Podcasting [seriously-simple-podcasting] <= 3.13.0 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Cross Site Request Forgery.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.

Affected:
up to 3.13.0
Fix:
No patched version reported
Disclosed:
Nov 21, 2025

CVE-2025-66061 on NVD →

Seriously Simple Podcasting [seriously-simple-podcasting] <= 3.13.0 (unfixed)

unknown

[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Retrieve Embedded Sensitive Data.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.

Affected:
up to 3.13.0
Fix:
No patched version reported
Disclosed:
Nov 21, 2025

CVE-2025-66059 on NVD →

Seriously Simple Podcasting <= 3.13.0 - Cross-Site Request Forgery

medium

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.13.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick...

CVSS:
4.3
Affected:
up to 3.13.0
Fixed in:
3.14.0
Disclosed:
Nov 11, 2025

CVE-2025-66061 on NVD →

Seriously Simple Podcasting <= 3.13.0 - Missing Authorization

medium

The Seriously Simple Podcasting plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.13.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.13.0
Fixed in:
3.14.0
Disclosed:
Nov 9, 2025

CVE-2025-66060 on NVD →

Seriously Simple Podcasting <= 3.13.0 - Unauthenticated Information Exposure

medium

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.13.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 3.13.0
Fixed in:
3.14.0
Disclosed:
Nov 9, 2025

CVE-2025-66059 on NVD →

Seriously Simple Podcasting [seriously-simple-podcasting] <= 3.13.0 (unfixed)

unknown

[en] Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.

Affected:
up to 3.13.0
Fix:
No patched version reported
Disclosed:
Oct 27, 2025

CVE-2025-62882 on NVD →

Seriously Simple Podcasting [seriously-simple-podcasting] <= 3.11.1 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows DOM-Based XSS.This issue affects Seriously Simple Podcasting: from n/a through <= 3.11.1.

Affected:
up to 3.11.1
Fix:
No patched version reported
Disclosed:
Oct 22, 2025

CVE-2025-49923 on NVD →

Seriously Simple Podcasting <= 3.11.1 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts i...

CVSS:
4.4
Affected:
up to 3.11.1
Fixed in:
3.12.0
Disclosed:
Aug 5, 2025

CVE-2025-49923 on NVD →

Seriously Simple Podcasting <= 3.13.0 - Missing Authorization

medium

The Seriously Simple Podcasting plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.13.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.13.0
Fixed in:
3.14.0
Disclosed:
Jun 12, 2025

CVE-2025-62882 on NVD →

Seriously Simple Podcasting [seriously-simple-podcasting] < 3.10.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting allows Stored XSS. This issue affects Seriously Simple Podcasting: from n/a through 3.9.0.

Affected:
up to 3.10.0
Fixed in:
3.10.0
Disclosed:
Apr 24, 2025

CVE-2025-46261 on NVD →

Seriously Simple Podcasting <= 3.9.0 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inj...

CVSS:
4.4
Affected:
up to 3.9.0
Fixed in:
3.10.0
Disclosed:
Apr 22, 2025

CVE-2025-46261 on NVD →

Seriously Simple Podcasting [seriously-simple-podcasting] < 3.6.0

unknown

[en] The Seriously Simple Podcasting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.5.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...

Affected:
up to 3.6.0
Fixed in:
3.6.0
Disclosed:
Nov 5, 2024

CVE-2024-9667 on NVD →

Seriously Simple Podcasting <= 3.5.0 - Reflected Cross-Site Scripting via add_query_arg Parameter

medium

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.5.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...

CVSS:
6.1
Affected:
up to 3.5.0
Fixed in:
3.6.0
Disclosed:
Nov 4, 2024

CVE-2024-9667 on NVD →

Seriously Simple Podcasting [seriously-simple-podcasting] < 3.3.0

unknown

[en] The Seriously Simple Podcasting WordPress plugin before 3.3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 3.3.0
Fixed in:
3.3.0
Disclosed:
Jul 13, 2024

CVE-2024-3751 on NVD →

Seriously Simple Podcasting <= 3.2.0 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,...

CVSS:
4.4
Affected:
up to 3.2.0
Fixed in:
3.3.0
Disclosed:
Jun 22, 2024

CVE-2024-3751 on NVD →

Seriously Simple Podcasting [seriously-simple-podcasting] < 3.1.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Castos Seriously Simple Podcasting allows Reflected XSS.This issue affects Seriously Simple Podcasting: from n/a through 3.0.2.

Affected:
up to 3.1.0
Fixed in:
3.1.0
Disclosed:
Mar 28, 2024

CVE-2024-25599 on NVD →

Seriously Simple Podcasting <= 3.0.2 - Reflected Cross-Site Scripting

medium

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...

CVSS:
6.1
Affected:
up to 3.0.2
Fixed in:
3.1.0
Disclosed:
Mar 26, 2024

CVE-2024-25599 on NVD →

Seriously Simple Podcasting [seriously-simple-podcasting] < 3.0.0

unknown

[en] The Seriously Simple Podcasting WordPress plugin before 3.0.0 discloses the Podcast owner's email address (which by default is the admin email address) via an unauthenticated crafted request.

Affected:
up to 3.0.0
Fixed in:
3.0.0
Disclosed:
Mar 11, 2024

CVE-2023-6444 on NVD →

Seriously Simple Podcasting <= 2.25.3 - Unauthenticated Email Disclosure

medium

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.25.3 via the source code. This makes it possible for unauthenticated attackers to extract product owner emails, which can be an administrators.

CVSS:
5.3
Affected:
up to 2.25.3
Fixed in:
3.0.0
Disclosed:
Feb 17, 2024

CVE-2023-6444 on NVD →

Seriously Simple Podcasting [seriously-simple-podcasting] < 2.19.1

unknown

[en] The Seriously Simple Podcasting WordPress plugin before 2.19.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege u...

Affected:
up to 2.19.1
Fixed in:
2.19.1
Disclosed:
Jan 16, 2023

CVE-2022-4571 on NVD →

Seriously Simple Podcasting <= 2.19.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

medium

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 2.19.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject...

CVSS:
6.4
Affected:
up to 2.19.0
Fixed in:
2.19.1
Disclosed:
Dec 21, 2022

CVE-2022-4571 on NVD →

Seriously Simple Podcasting <= 2.16.0 - Cross-Site Request Forgery

high

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.16.0. This is due to missing or incorrect nonce validation on the save_step function as well as other functions related to onboarding. This makes it possible for unauthenticated attackers...

CVSS:
8.8
Affected:
up to 2.16.0
Fixed in:
2.16.1
Disclosed:
Sep 23, 2022

CVE-2022-40132 on NVD →

Seriously Simple Podcasting [seriously-simple-podcasting] < 2.16.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Seriously Simple Podcasting plugin <= 2.16.0 at WordPress, leading to plugin settings change.

Affected:
up to 2.16.1
Fixed in:
2.16.1
Disclosed:
Sep 23, 2022

CVE-2022-40132 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database