Impact
The vulnerability is a Cross‑Site Request Forgery that allows an attacker to inject malicious script into the WP Simple Sitemap plugin’s stored data. The likely attack vector is a CSRF request that causes the plugin to persist user‑supplied content, which is then executed in the browser of any user who views the affected sitemap. This stored XSS could enable session hijacking, defacement, or data exfiltration.
Affected Systems
Affected product: Jenst WP Simple Sitemap. Versions up to and including 0.2 are impacted. No additional version details are available.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to craft a CSRF request against a logged‑in user, which can be performed remotely with access to the site’s URL. The impact is limited to users who load the stored sitemap content.
OpenCVE Enrichment
EUVD