Record summary

CVE-2022-0346 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an arbitrary value, thus causing XSS via error message or RCE if allow_url_include is turned on.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 2, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

XML Sitemap Generator for Google

CVE List2.0.4 to < 2.0.4affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress XML Sitemap Generator for Google <2.0.4 - Cross-Site Scripting/Remote Code ExecutionCVSS 6.1

WordPress XML Sitemap Generator for Google plugin before 2.0.4 contains a cross-site scripting vulnerability that can lead to remote code execution. It does not validate a parameter which can be set to an arbitrary value, thus causing cross-site scripting via error message or remote code execution if allow_url_include is turned on.

Impact

Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code on the affected system or inject malicious scripts into web pages viewed by users.

Remediation

Update the WordPress XML Sitemap Generator for Google plugin to version 2.0.4 or later to mitigate the XSS and RCE vulnerabilities.

WeaknessesCWE-79
AuthorsAkincibor, theamanrawat
Template tagscve2022cvewpscanwpwordpresswp-pluginxsswww-xml-sitemap-generator-orgxmlsitemapgeneratorvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:xmlsitemapgenerator:xml_sitemap_generator:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2