CVE-2024-25599: WordPress Seriously Simple Podcasting plugin <= 3.0.2 - Reflected Cross Site Scripting (XSS) vulnerability
Published Mar 28, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting.This issue affects Seriously Simple Podcasting: from n/a through <= 3.0.2.
Affected Software
3 affected components
Castos Seriously Simple Podcasting<=3.0.2
WordPress Seriously Simple Podcasting<=3.0.2
Castos Seriously Simple Podcasting Wordpress<3.1.0
Remediation
Information
Update to 3.1.0 or a higher version.
Event History
Mar 28, 2024
CVE Published
via MITRE·06:52 AM
Data Sourced
via MITRE·06:52 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25599?
CVE-2024-25599 is classified as a reflected Cross-site Scripting (XSS) vulnerability.
2
What versions of Seriously Simple Podcasting are affected by CVE-2024-25599?
CVE-2024-25599 affects Seriously Simple Podcasting versions from n/a up to and including 3.0.2.
3
How do I fix CVE-2024-25599?
To fix CVE-2024-25599, update to the latest version of Seriously Simple Podcasting beyond 3.0.2.
4
What type of vulnerability is CVE-2024-25599?
CVE-2024-25599 is an improper neutralization of input during web page generation resulting in reflected XSS.
5
Can CVE-2024-25599 impact WordPress installations?
Yes, CVE-2024-25599 affects the Seriously Simple Podcasting plugin used in WordPress versions up to and including 3.0.2.