CVE-2024-3751: Seriously Simple Podcasting < 3.3.0 - Admin+ Stored XSS
The Seriously Simple Podcasting WordPress plugin before 3.3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3751?
CVE-2024-3751 is considered a high severity vulnerability due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-3751?
To fix CVE-2024-3751, update the Seriously Simple Podcasting plugin to version 3.3.0 or later.
Who is affected by CVE-2024-3751?
CVE-2024-3751 affects users of the Seriously Simple Podcasting WordPress plugin versions before 3.3.0, especially those with high privilege accounts.
What type of attack does CVE-2024-3751 permit?
CVE-2024-3751 allows high privilege users to perform Stored Cross-Site Scripting (XSS) attacks.
Is CVE-2024-3751 exploitable without the unfiltered_html capability?
Yes, CVE-2024-3751 can be exploited even when the unfiltered_html capability is disallowed for users.