cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forseriously-simple-podcasting seriously-simple-podcasting

Direction: ascending
Jun 07, 2024

Seriously Simple Podcasting # CVE-2022-40132

CVE, Research URL

CVE-2022-40132

Date
Sep 24, 2022
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Seriously Simple Podcasting plugin <= 2.16.0 at WordPress, leading to plugin settings change.
Affected versions
Min -, max -.
Status
vulnerable

Seriously Simple Podcasting # CVE-2024-25599

CVE, Research URL

CVE-2024-25599

Date
Mar 28, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Castos Seriously Simple Podcasting allows Reflected XSS.This issue affects Seriously Simple Podcasting: from n/a through 3.0.2.
Affected versions
Min -, max -.
Status
vulnerable

Seriously Simple Podcasting # CVE-2022-4571

CVE, Research URL

CVE-2022-4571

Date
Jan 16, 2023
Research Description
The Seriously Simple Podcasting WordPress plugin before 2.19.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Affected versions
Min -, max -.
Status
vulnerable

Seriously Simple Podcasting # CVE-2023-6444

CVE, Research URL

CVE-2023-6444

Date
Mar 11, 2024
Research Description
The Seriously Simple Podcasting WordPress plugin before 3.0.0 discloses the Podcast owner's email address (which by default is the admin email address) via an unauthenticated crafted request.
Affected versions
Min -, max -.
Status
vulnerable
Jul 15, 2024

Seriously Simple Podcasting # CVE-2024-3751

CVE, Research URL

CVE-2024-3751

Date
Jul 13, 2024
Research Description
The Seriously Simple Podcasting WordPress plugin before 3.3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Affected versions
Min -, max -.
Status
vulnerable
Nov 05, 2024

Seriously Simple Podcasting # CVE-2024-9667

CVE, Research URL

CVE-2024-9667

Date
Nov 05, 2024
Research Description
The Seriously Simple Podcasting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.5.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable
Apr 23, 2025

Seriously Simple Podcasting # CVE-2025-46261

CVE, Research URL

CVE-2025-46261

Date
-
Research Description
Seriously Simple Podcasting [seriously-simple-podcasting] < 3.10.0 CVE-2025-46261
Affected versions
Min -, max -.
Status
vulnerable