Junglewise Threat Intelligence

CVE-2026-39505: Craig Hewitt Seriously Simple Podcasting missing authorization

CVE-2026-39505 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

Seriously Simple Podcasting is a popular WordPress plugin used to manage and host podcast content directly from a website. A security flaw in the plugin's access control settings could allow unauthorized individuals to access information or perform actions that should be restricted to administrators. This could lead to the exposure of internal data or unauthorized changes to podcast configurations.

Technical details

A missing authorization (CWE-862) vulnerability exists in the Seriously Simple Podcasting plugin for WordPress in versions up to and including 3.14.2. The flaw stems from a failure to properly validate user permissions or implement sufficient nonce checks on certain functions, leading to broken access control. An unauthenticated remote attacker can exploit this to perform actions or access data that should require higher privilege levels. The issue is resolved in version 3.14.3.

Affected products

  • Craig Hewitt (Castos) Seriously Simple Podcasting <= 3.14.2

Timeline

  • 2026-02-24: other: Reported by hivesec
  • 2026-03-26: advisory: Patchstack advisory published
  • 2026-04-08: disclosed: CVE published
  • 2026-03-26: patched: Version 3.14.3 released

References