CVE-2025-46261: WordPress Seriously Simple Podcasting plugin <= 3.9.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Stored XSS.This issue affects Seriously Simple Podcasting: from n/a through <= 3.9.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46261?
CVE-2025-46261 has been classified as a high severity Stored XSS vulnerability.
How do I fix CVE-2025-46261?
To fix CVE-2025-46261, update Seriously Simple Podcasting to version 3.9.1 or later.
What versions of Seriously Simple Podcasting are affected by CVE-2025-46261?
CVE-2025-46261 affects all versions of Seriously Simple Podcasting up to and including 3.9.0.
What type of vulnerability is CVE-2025-46261?
CVE-2025-46261 is an Improper Neutralization of Input During Web Page Generation vulnerability that leads to Stored Cross-site Scripting.
Who is the vendor for CVE-2025-46261?
The vendor for CVE-2025-46261 is Craig Hewitt, the creator of the Seriously Simple Podcasting plugin.