Plugin Vulnerability Hub
Plugin 15 known issues Latest disclosed Mar 26, 2026

Seriously Simple Podcasting Vulnerabilities

Review known vulnerability records for the WordPress plugin Seriously Simple Podcasting (`seriously-simple-podcasting`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-39505, CVE-2026-24360 and CVE-2026-24952, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
15
High or Critical
1
Patch Coverage
100%
Last Updated
Apr 15, 2026
Priority CVE Quick Links

Fast paths into Seriously Simple Podcasting CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
15
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Seriously Simple Podcasting so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
15 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 1 high severity finding.
Recent CVEs
CVE-2026-39505, CVE-2026-24360 and CVE-2026-24952
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Seriously Simple Podcasting

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-39505
CVE-2026-39505: Seriously Simple Podcasting <= 3.14.2 - Missing Authorization

The Seriously Simple Podcasting plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.14.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Published
Mar 26, 2026
Patched Release
3.14.3
Affected Versions
Versions up to 3.14.2
Next Step
Update to 3.14.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-24360
CVE-2026-24360: Seriously Simple Podcasting <= 3.14.1 - Authenticated (Editor+) Server-Side Request Forgery

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.14.1. This makes it possible for authenticated attackers, with Editor-level access and above, to make web requests to arbitrary locations orig...

Published
Jan 13, 2026
Patched Release
3.14.2
Affected Versions
Versions up to 3.14.1
Next Step
Update to 3.14.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-24952
CVE-2026-24952: Seriously Simple Podcasting <= 3.14.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.14.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access...

Published
Dec 21, 2025
Patched Release
3.14.2
Affected Versions
Versions up to 3.14.1
Next Step
Update to 3.14.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-66061
CVE-2025-66061: Seriously Simple Podcasting <= 3.13.0 - Cross-Site Request Forgery

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.13.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an un...

Published
Nov 11, 2025
Patched Release
3.14.0
Affected Versions
Versions up to 3.13.0
Next Step
Update to 3.14.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-66060
CVE-2025-66060: Seriously Simple Podcasting <= 3.13.0 - Missing Authorization

The Seriously Simple Podcasting plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.13.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Published
Nov 09, 2025
Patched Release
3.14.0
Affected Versions
Versions up to 3.13.0
Next Step
Update to 3.14.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-66059
CVE-2025-66059: Seriously Simple Podcasting <= 3.13.0 - Unauthenticated Information Exposure

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.13.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

Published
Nov 09, 2025
Patched Release
3.14.0
Affected Versions
Versions up to 3.13.0
Next Step
Update to 3.14.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-49923
CVE-2025-49923: Seriously Simple Podcasting <= 3.11.1 - Authenticated (Editor+) Stored Cross-Site Scripting

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and...

Published
Aug 05, 2025
Patched Release
3.12.0
Affected Versions
Versions up to 3.11.1
Next Step
Update to 3.12.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-62882
CVE-2025-62882: Seriously Simple Podcasting <= 3.13.0 - Missing Authorization

The Seriously Simple Podcasting plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.13.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perfo...

Published
Jun 12, 2025
Patched Release
3.14.0
Affected Versions
Versions up to 3.13.0
Next Step
Update to 3.14.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-46261
CVE-2025-46261: Seriously Simple Podcasting <= 3.9.0 - Authenticated (Editor+) Stored Cross-Site Scripting

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with ed...

Published
Apr 22, 2025
Patched Release
3.10.0
Affected Versions
Versions up to 3.9.0
Next Step
Update to 3.10.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-9667
CVE-2024-9667: Seriously Simple Podcasting <= 3.5.0 - Reflected Cross-Site Scripting via add_query_arg Parameter

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.5.0. This makes it possible for unauthenticated attackers to inject...

Published
Nov 04, 2024
Patched Release
3.6.0
Affected Versions
Versions up to 3.5.0
Next Step
Update to 3.6.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-3751
CVE-2024-3751: Seriously Simple Podcasting <= 3.2.0 - Authenticated (Admin+) Stored Cross-Site Scripting

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with ad...

Published
Jun 22, 2024
Patched Release
3.3.0
Affected Versions
Versions up to 3.2.0
Next Step
Update to 3.3.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-25599
CVE-2024-25599: Seriously Simple Podcasting <= 3.0.2 - Reflected Cross-Site Scripting

The Seriously Simple Podcasting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary we...

Published
Mar 26, 2024
Patched Release
3.1.0
Affected Versions
Versions up to 3.0.2
Next Step
Update to 3.1.0 or newer if supported.