Lucene search

K
wpvulndbKrzysztof Zając (CERT PL)WPVDB-ID:061C59D6-F4A0-4CD1-B945-5E92B9C2B4AA
HistoryFeb 17, 2024 - 12:00 a.m.

Seriously Simple Podcasting < 3.0.0 - Unauthenticated Administrator Email Disclosure

2024-02-1700:00:00
Krzysztof Zając (CERT PL)
wpscan.com
5
plugin
email
unauthenticated
request
fix
upgrade
feed details

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

22.6%

Description The plugin discloses the Podcast owner’s email address (which by default is the admin email address) via an unauthenticated crafted request. This was fixed in 3.0.0 for new plugin installation, however when upgrading, users will have to unset the “Owner email address” in the Feed Details settings

PoC

View the source of the page below and notice the email being disclosed: https://example.com/?feed=itunes https://example.com/feed/podcast/

AI Score

6.6

Confidence

High

EPSS

0.001

Percentile

22.6%

Related for WPVDB-ID:061C59D6-F4A0-4CD1-B945-5E92B9C2B4AA