WordPress security by component
Seriously Simple Podcasting
Plugin description
Seriously Simple Podcasting is a WordPress component with 15 published CVE records in this archive. The latest tracked vulnerability was published Apr 08, 2026; the highest CVE/CNA score is 7.1.
Plugin slug:
seriously-simple-podcastingLatest vulnerability
CVE-2026-39505: Seriously Simple Podcasting: A security weakness
Seriously Simple Podcasting is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.14.2.
| Safe version |
|
||
|---|---|---|---|
| Apr 08, 2026 |
CVE-2026-39505
Seriously Simple Podcasting: A security weakness
Seriously Simple Podcasting is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.14.2.
|
3.14.3 |
CVE5.3
NVDPending
|
| Feb 03, 2026 |
CVE-2026-24952
Seriously Simple Podcasting: Cross-site scripting
Seriously Simple Podcasting is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jan 22, 2026 |
CVE-2026-24360
Seriously Simple Podcasting: Server-side request forgery
Seriously Simple Podcasting is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE4.4
NVDPending
|
| Nov 21, 2025 |
CVE-2025-66061
Seriously Simple Podcasting: Cross-site request forgery
Seriously Simple Podcasting is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Nov 21, 2025 |
CVE-2025-66060
Seriously Simple Podcasting: A security weakness
Seriously Simple Podcasting is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Nov 21, 2025 |
CVE-2025-66059
Seriously Simple Podcasting: A security weakness
Seriously Simple Podcasting is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Oct 27, 2025 |
CVE-2025-62882
Seriously Simple Podcasting: A security weakness
Seriously Simple Podcasting is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Oct 22, 2025 |
CVE-2025-49923
Seriously Simple Podcasting: Cross-site scripting
Seriously Simple Podcasting is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Apr 24, 2025 |
CVE-2025-46261
Seriously Simple Podcasting: Cross-site scripting
Seriously Simple Podcasting is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Nov 05, 2024 |
CVE-2024-9667
Seriously Simple Podcasting: Cross-site scripting
Seriously Simple Podcasting is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Jul 13, 2024 |
CVE-2024-3751
Seriously Simple Podcasting: Cross-site scripting
Seriously Simple Podcasting is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| Mar 28, 2024 |
CVE-2024-25599
Seriously Simple Podcasting: Cross-site scripting
Seriously Simple Podcasting is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Mar 11, 2024 |
CVE-2023-6444
Seriously Simple Podcasting: A security weakness
Seriously Simple Podcasting is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jan 16, 2023 |
CVE-2022-4571
Seriously Simple Podcasting: Cross-site scripting
Seriously Simple Podcasting is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Sep 23, 2022 |
CVE-2022-40132
Seriously Simple Podcasting: Cross-site request forgery
Seriously Simple Podcasting is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD4.3
|