CVE-2022-40132 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Seriously Simple Podcasting plugin up to version 2.16.0 for WordPress. This flaw allows an unauthenticated attacker to manipulate plugin settings if a logged-in administrator is tricked into clicking a malicious link. The vulnerability has a CVSS score of 4.3 (Medium), indicating a low impact on integrity (I:L) and no impact on confidentiality or availability. Its attack vector is network-based, but requires user interaction (UI:R) and low attack complexity (AC:L). Currently, there is no evidence of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.16.0CPE matchmatch criteria | cpe:2.3:a:castos:seriously_simple_podcasting:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.