CVE-2023-6444: Seriously Simple Podcasting < 3.0.0 - Unauthenticated Administrator Email Disclosure
Published Mar 11, 2024
·Updated
The Seriously Simple Podcasting WordPress plugin before 3.0.0 discloses the Podcast owner's email address (which by default is the admin email address) via an unauthenticated crafted request.
Affected Software
2 affected components
Castos Seriously Simple Podcasting Wordpress<3.0.0
Podcasting Seriously Simple Podcasting<3.0.0
Event History
Mar 11, 2024
CVE Published
via MITRE·05:56 PM
Data Sourced
via MITRE·05:56 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2023-6444?
CVE-2023-6444 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2023-6444?
To fix CVE-2023-6444, update the Seriously Simple Podcasting plugin to version 3.0.0 or later.
3
What information does CVE-2023-6444 disclose?
CVE-2023-6444 discloses the Podcast owner's email address via an unauthenticated crafted request.
4
Who is affected by CVE-2023-6444?
Users of the Seriously Simple Podcasting WordPress plugin before version 3.0.0 are affected by CVE-2023-6444.
5
Is there a workaround for CVE-2023-6444?
There is no known workaround for CVE-2023-6444; upgrading the plugin is the recommended action.