What the vulnerability does
01Description
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ashish Ajani WordPress Simple HTML Sitemap plugin <= 2.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ashish Ajani WordPress Simple HTML Sitemap plugin <= 2.1 versions.
Explanation of Vulnerability in Simple Terms
The WordPress Simple HTML Sitemap plugin through version 2.1 contains a stored cross-site scripting (XSS) vulnerability. An authenticated user with low privileges can inject malicious scripts into the sitemap configuration. When other users view the affected page, the scripts execute in their browsers, potentially allowing session hijacking or credential theft. The vulnerability requires user interaction to trigger.
What an attacker can do
Inject malicious scripts that execute in other users' browsers when they view the sitemap.
Potential impact on your site
Authenticated users can inject scripts affecting other site visitors, risking account compromise or data theft.
Conditions required to exploit
Attacker must have a low-privilege WordPress account and the victim must visit the affected page.
Key dates
External resources
Related vulnerabilities