CVE-2022-0952
HIGH EXPLOITED NUCLEISitemap < 1.0.36 - Missing Authorization
Title source: ruleDescription
The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register and default_role, allowing them to create a new admin account and take over the blog.
Exploits (1)
nomisec
WORKING POC
4 stars
by RandomRobbieBF · client-side
https://github.com/RandomRobbieBF/CVE-2022-0952
Nuclei Templates (1)
WordPress Sitemap by click5 <1.0.36 - Missing Authorization
HIGHVERIFIEDby random-robbie
Scores
CVSS v3
8.8
EPSS
0.8919
EPSS Percentile
99.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation Intel
VulnCheck KEV
2024-01-02
Classification
CWE
CWE-862
CWE-352
Status
published
Affected Products (1)
sitemap_project/sitemap
< 1.0.36
Timeline
Published
May 02, 2022
Tracked Since
Feb 18, 2026