plugin

Simple Podcasting Vulnerabilities

5 known security issues reported for the Simple Podcasting WordPress plugin. Most recent disclosed Feb 23, 2023.

1 critical 2 high 1 medium 1 low

Running Simple Podcasting on your site? Check whether your installed version is affected.

Scan your site free

simple-git < 3.16.0 - Remote Code Execution

high

The package simple-git is vulnerable to Remote Code Execution in versions before 3.16.0 via the clone(), pull(), push() and listRemote() methods due to improper input sanitization. This is due to an incomplete fix of CVE-2022-25912. WordPress plugins and themes may be using this package, however, they may not be vulner...

CVSS:
8.1
Affected:
up to 1.4.0
Fixed in:
1.5.0
Disclosed:
Feb 23, 2023

CVE-2022-25860 on NVD →

json5 <= 1.0.1 and 2.0.0-2.2.1 - Prototype Pollution

high

The package json5 before 1.0.2 and between 2.0.0 and 2.2.1 inclusive is vulnerable to prototype pollution due to failure to restrict parsing of keys named `__proto__`. As this package is used in some WordPress plugins, this could result in the impacted plugins being vulnerable.

CVSS:
8.8
Affected:
up to 1.3.0
Fixed in:
1.4.0
Disclosed:
Dec 23, 2022

CVE-2022-46175 on NVD →

simple-git < 3.15.0 - Remote Code Execution

critical

The package simple-git is vulnerable to Remote Code Execution in versions before 3.15.0 when the ext transport protocol is enabled. This makes the vulnerability exploitable using the clone method. WordPress plugins and themes may be using this package, however, may not be vulnerable to exploitation.

CVSS:
9.8
Affected:
up to 1.3.0
Fixed in:
1.4.0
Disclosed:
Dec 5, 2022

CVE-2022-25912 on NVD →

terser (JS Package) < 5.14.2 - Denial of Service

low

The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions. Some WordPress plugins and themes use this dependency, however, are not vulnerable to exploitation.

CVSS:
3.7
Affected:
up to 1.2.4
Fixed in:
1.2.4
Disclosed:
Jul 14, 2022

CVE-2022-25858 on NVD →

got (JS Package) <= 11.8.4 and 12.0-<12.1.0 - Open Redirect

medium

The got (JS Package) is vulnerable to Open Redirect in versions up to, and including, 11.8.4 as well as from 12 to below 12.1.0. Requested URLs are not verified and allow open redirection to a local UNIX socket.

CVSS:
5.3
Affected:
up to 1.2.4
Fixed in:
1.3.0
Disclosed:
Jun 19, 2022

CVE-2022-33987 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database