What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in WPGrim Dynamic XML Sitemaps Generator for Google plugin <= 1.3.3 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in WPGrim Dynamic XML Sitemaps Generator for Google plugin <= 1.3.3 versions.
Explanation of Vulnerability in Simple Terms
Dynamic XML Sitemaps Generator for Google versions up to 1.3.3 contain a cross-site request forgery (CSRF) vulnerability. An attacker can craft a malicious webpage that, when visited by a site administrator, performs unwanted actions on the plugin without their knowledge. The vulnerability requires no special privileges but does require the admin to visit a malicious link. This can lead to unauthorized changes to sitemap settings or other plugin configurations.
What an attacker can do
Trick a site admin into visiting a malicious page that modifies plugin settings or performs unwanted actions.
Potential impact on your site
An attacker can alter your sitemap configuration or plugin settings by tricking you into clicking a malicious link.
Conditions required to exploit
Site admin must visit an attacker-controlled webpage while logged into WordPress.
Key dates
External resources
Related vulnerabilities