CVE-2025-49923: WordPress Seriously Simple Podcasting plugin <= 3.11.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows DOM-Based XSS.This issue affects Seriously Simple Podcasting: from n/a through <= 3.11.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49923?
CVE-2025-49923 is rated as a medium severity vulnerability due to its potential impact on web security.
How do I fix CVE-2025-49923?
To fix CVE-2025-49923, update Seriously Simple Podcasting to the latest version after 3.11.1.
What kind of vulnerability is identified by CVE-2025-49923?
CVE-2025-49923 is an improper neutralization of input during web page generation, leading to a Cross-site Scripting (XSS) vulnerability.
Which versions of Seriously Simple Podcasting are affected by CVE-2025-49923?
CVE-2025-49923 affects Seriously Simple Podcasting versions from n/a to 3.11.1.
Is CVE-2025-49923 related to any specific software platforms?
Yes, CVE-2025-49923 is related to the Seriously Simple Podcasting plugin for WordPress.