Unrated severityNVD Advisory· Published May 23, 2022· Updated Aug 2, 2024
Google XML Sitemap Generator < 2.0.4 - Reflected Cross-Site Scripting
CVE-2022-0346
Description
The XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an arbitrary value, thus causing XSS via error message or RCE if allow_url_include is turned on.
Affected products
1- Range: <2.0.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/4b339390-d71a-44e0-8682-51a12bd2bfe6mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.