Castos Seriously Simple Podcasting vulnerable to Reflected XSS
CVE-2024-25599
7.1HIGH
What is CVE-2024-25599?
The vulnerability in Castos Seriously Simple Podcasting allows for Reflected Cross-Site Scripting (XSS) attacks, jeopardizing the security of web pages generated by the plugin. This flaw enables attackers to inject malicious scripts into content viewed by users. If exploited, this could lead to unauthorized actions being executed in the context of the user’s session, risking sensitive data and user privacy. Affected versions range from an unspecified version up to 3.0.2, making it essential for users to assess their installations and apply necessary updates to mitigate this risk.
Affected Version(s)
Seriously Simple Podcasting 0 <= 3.0.2