What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Videos plugin <= 2.6.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Videos plugin <= 2.6.1 versions.
Explanation of Vulnerability in Simple Terms
Google XML Sitemap for Videos through version 2.6.1 is vulnerable to cross-site request forgery (CSRF). An attacker can trick a site administrator into performing unwanted actions—such as modifying plugin settings or generating sitemaps—by crafting a malicious link or page. The vulnerability requires the admin to click the link while logged in, but causes only minor changes to site configuration, not data loss or unauthorized access.
What an attacker can do
Trick a logged-in admin into changing plugin settings or generating sitemaps without their knowledge.
Potential impact on your site
Plugin settings could be altered by an attacker, potentially affecting your video sitemap generation and SEO.
Conditions required to exploit
Admin must click a malicious link or visit an attacker-controlled page while logged into WordPress.
Key dates
External resources
Related vulnerabilities