Description
Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.
Published: 2025-10-27
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from an incorrect configuration of access control within the Seriously Simple Podcasting plugin for WordPress. The missing authorization check allows an attacker to perform actions that should be restricted to privileged users, potentially leading to unauthorized modification or exposure of podcast content. The weakness is identified as a broken access control issue (CWE-862).

Affected Systems

This flaw affects the Seriously Simple Podcasting plugin developed by Craig Hewitt for WordPress. Versions from the earliest release up to and including 3.13.0 are vulnerable. All deployments using these versions should be considered at risk.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate impact, while the EPSS score of less than 1% suggests a very low probability of exploitation at this time. The plugin is not listed in the CISA KEV catalog. The likely attack vector is remote, via the WordPress web interface, since the plugin’s administrative endpoints are exposed over HTTP. An attacker who can send crafted requests to these endpoints could trigger the unauthorized actions without needing prior authentication, assuming the site allows access to the plugin’s administrative URLs. No reasonable preconditions are stated in the description, so the exploitation appears possible from any user with basic site access.

Generated by OpenCVE AI on April 29, 2026 at 20:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Seriously Simple Podcasting to version 3.13.1 or later, which removes the broken access control check.
  • If an upgrade is not immediately possible, restrict the plugin’s admin pages to administrators only using WordPress role management or .htaccess rules.
  • Verify that the WordPress instance disables XML‑RPC or other indirect access that may expose the plugin’s endpoints.

Generated by OpenCVE AI on April 29, 2026 at 20:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Fri, 05 Dec 2025 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Castos
Castos seriously Simple Podcasting
CPEs cpe:2.3:a:castos:seriously_simple_podcasting:*:*:*:*:*:wordpress:*:*
Vendors & Products Castos
Castos seriously Simple Podcasting

Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Mon, 27 Oct 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Craig Hewitt
Craig Hewitt seriously Simple Podcasting
Wordpress
Wordpress wordpress
Vendors & Products Craig Hewitt
Craig Hewitt seriously Simple Podcasting
Wordpress
Wordpress wordpress

Mon, 27 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Oct 2025 02:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seriously Simple Podcasting: from n/a through <= 3.13.0.
Title WordPress Seriously Simple Podcasting plugin <= 3.13.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Castos Seriously Simple Podcasting
Craig Hewitt Seriously Simple Podcasting
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:04.807Z

Reserved: 2025-10-24T14:24:07.765Z

Link: CVE-2025-62882

cve-icon Vulnrichment

Updated: 2025-10-27T15:25:42.572Z

cve-icon NVD

Status : Modified

Published: 2025-10-27T02:15:46.940

Modified: 2026-04-27T17:16:34.030

Link: CVE-2025-62882

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T21:00:09Z

Weaknesses