CVE-2023-25055 MEDIUM

CVE-2023-25055: WordPress Google XML Sitemap for Videos Plugin <= 2.6.1 is vulnerable to Cross Site Request Forgery (CSRF)

Vendor Amit Agarwal
Product Google XML Sitemap for Videos
Weakness CWE-352 · CSRF
Published June 15, 2023
Last update April 28, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Videos plugin <= 2.6.1 versions.

Explanation of Vulnerability in Simple Terms

02Summary

Google XML Sitemap for Videos through version 2.6.1 is vulnerable to cross-site request forgery (CSRF). An attacker can trick a site administrator into performing unwanted actions—such as modifying plugin settings or generating sitemaps—by crafting a malicious link or page. The vulnerability requires the admin to click the link while logged in, but causes only minor changes to site configuration, not data loss or unauthorized access.

What an attacker can do

03Attacker Capabilities

Trick a logged-in admin into changing plugin settings or generating sitemaps without their knowledge.

Potential impact on your site

04Site Impact

Plugin settings could be altered by an attacker, potentially affecting your video sitemap generation and SEO.

Conditions required to exploit

05Prerequisites

Admin must click a malicious link or visit an attacker-controlled page while logged into WordPress.

Key dates

06Disclosure timeline

June 15, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE