CVE-2023-6444
Seriously Simple Podcasting < 3.0.0 - Unauthenticated Administrator Email Disclosure
Record summary
CVE-2023-6444 has a selected CVSS score of 5.3 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
The Seriously Simple Podcasting WordPress plugin before 3.0.0 discloses the Podcast owner's email address (which by default is the admin email address) via an unauthenticated crafted request.
Exploitation context
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Seriously Simple PodcastingDefault status: unaffected | CVE List | Before 3.0.0 | affected |
seriously_simple_podcastingBrowse castos / seriously_simple_podcastingDefault status: unaffected | CVE List | Before 3.0.0 | affected |
Proofs of concept
1Repository PoCs
GitHubWayne-Ker/CVE-2023-6444-POCRepository PoCby Wayne-KerStars: 0Not analyzed2 files
Nuclei templates
1ProjectDiscoveryMEDIUMSeriously Simple Podcasting < 3.0.0 - Information DisclosureCVSS 5.3
The Seriously Simple Podcasting WordPress plugin before 3.0.0 discloses the Podcast owner's email address (which by default is the admin email address) via an unauthenticated crafted request.
Impact
Unauthenticated attackers can send crafted requests to obtain podcast owner email addresses which typically reveal administrator email addresses, enabling targeted phishing attacks.
Remediation
Fixed in 3.0.0
Source: ProjectDiscovery