Impact
The vulnerability is a missing authorization flaw that allows attackers to exploit incorrectly configured access control settings within the Seriously Simple Podcasting plugin. This issue, classified as CWE-862, can enable an attacker to perform actions normally restricted to privileged roles, such as creating, editing, or deleting podcast content, thereby compromising the integrity and confidentiality of the site’s media assets.
Affected Systems
WordPress sites that have installed the Seriously Simple Podcasting plugin by Craig Hewitt to any version up to and including 3.13.0 are affected. Updating the plugin beyond version 3.13.0 removes the vulnerability.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, while the EPSS score of less than 1% suggests a low exploitation probability at present, and the flaw is not listed in CISA KEV. The typical attack vector is inferred to involve a user with limited privileges who gains unauthorized access through the plugin’s interface or API; the exact prerequisites are not explicitly documented, but it is reasonable to assume an authenticated user without elevated rights may be sufficient.
OpenCVE Enrichment