CVE-2023-6444: Castos Seriously Simple Podcasting

Medium severity, CVSS 5.3. EPSS: 2.5% chance of exploitation in the next 30 days.

The Seriously Simple Podcasting WordPress plugin before 3.0.0 discloses the Podcast owner's email address (which by default is the admin email address) via an unauthenticated crafted request.

Affected products

  • Castos Seriously Simple Podcasting: before 3.0.0 (fixed in 3.0.0)

Published 2024-03-11. Last modified 2026-06-17.