Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows DOM-Based XSS.This issue affects Seriously Simple Podcasting: from n/a through <= 3.11.1.
Published: 2025-10-22
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a DOM‑based Cross‑Site Scripting flaw that allows a malicious actor to inject and execute arbitrary JavaScript within the context of a victim’s browser. This type of flaw falls under CWE‑79 and can lead to session hijacking, defacement, or the delivery of malicious payloads to users who visit affected pages. The impact is limited to the victim’s browser; it does not compromise the server itself.

Affected Systems

Craig Hewitt’s Seriously Simple Podcasting plugin for WordPress is affected for all versions up to and including 3.11.1. Sites running these plugin versions on any WordPress installation are vulnerable.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate risk. The EPSS score of less than 1% suggests that the likelihood of exploitation in the wild is low, and the flaw is not currently listed in CISA’s KEV catalog. However, because the attack can be triggered by a crafted URL or input that reaches the plugin, a determined attacker could target active users and generate malicious scripts that run in their browsers. The primary attack vector is DOM-based XSS via the plugin’s web interface, inferred from the description and the nature of the flaw. No additional exploitation prerequisites are stated in the provided data.

Generated by OpenCVE AI on April 30, 2026 at 05:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Seriously Simple Podcasting to the latest available version (greater than 3.11.1).
  • If an immediate update is not possible, disable or uninstall the plugin to remove the attack surface until a patch can be applied.
  • Ensure the WordPress core and all other security‑related plugins are kept current to reduce overall exposure to other vulnerabilities.

Generated by OpenCVE AI on April 30, 2026 at 05:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Fri, 05 Dec 2025 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Castos
Castos seriously Simple Podcasting
CPEs cpe:2.3:a:castos:seriously_simple_podcasting:*:*:*:*:*:wordpress:*:*
Vendors & Products Castos
Castos seriously Simple Podcasting

Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 23 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Craighewitt
Craighewitt seriously Simple Podcasting
Wordpress
Wordpress wordpress
Vendors & Products Craighewitt
Craighewitt seriously Simple Podcasting
Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows DOM-Based XSS.This issue affects Seriously Simple Podcasting: from n/a through <= 3.11.1.
Title WordPress Seriously Simple Podcasting plugin <= 3.11.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Castos Seriously Simple Podcasting
Craighewitt Seriously Simple Podcasting
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:07.972Z

Reserved: 2025-06-11T16:06:59.983Z

Link: CVE-2025-49923

cve-icon Vulnrichment

Updated: 2025-10-23T15:31:16.924Z

cve-icon NVD

Status : Modified

Published: 2025-10-22T15:15:38.193

Modified: 2026-04-27T20:16:17.617

Link: CVE-2025-49923

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T06:00:12Z

Weaknesses