CVE-2022-0952

HIGH EXPLOITED NUCLEI

Sitemap by click5 < 1.0.36 - Unauthenticated Arbitrary Option Update via REST Endpoint

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2022-0952 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including RandomRobbieBF. A Nuclei detection template is also available.

AI-analyzed exploit summary This PoC exploits CVE-2022-0952, an unauthenticated arbitrary options update vulnerability in the Sitemap by click5 WordPress plugin. It allows attackers to enable user registration and set the default role to administrator, enabling account creation with admin privileges.

Description

The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register and default_role, allowing them to create a new admin account and take over the blog.

Exploits (1)

nomisec WORKING POC 4 stars
by RandomRobbieBF · client-side
https://github.com/RandomRobbieBF/CVE-2022-0952

This PoC exploits CVE-2022-0952, an unauthenticated arbitrary options update vulnerability in the Sitemap by click5 WordPress plugin. It allows attackers to enable user registration and set the default role to administrator, enabling account creation with admin privileges.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Sitemap by click5 < 1.0.36
No auth needed
Prerequisites: WordPress site with vulnerable plugin installed · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

WordPress Sitemap by click5 <1.0.36 - Missing Authorization
HIGHVERIFIEDby random-robbie

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/0f694961-afab-44f9-846c-e80a0f6c768b

Scores

CVSS v3 8.8
EPSS 0.1252
EPSS Percentile 95.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2024-01-02
CWE
CWE-862 CWE-352
Status published
Products (1)
sitemap_project/sitemap < 1.0.36
Published May 02, 2022
Tracked Since Feb 18, 2026