Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digireturn DN Sitemap Control dn-sitemap-control allows Reflected XSS.This issue affects DN Sitemap Control: from n/a through <= 1.0.6.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation that allows reflected cross‑site scripting in the DN Sitemap Control WordPress plugin up to version 1.0.6. The plugin reflects unsanitized user‑supplied data back into the HTTP response, enabling an attacker to inject and execute arbitrary JavaScript in a victim’s browser. Exploitation can lead to session hijacking, credential theft, defacement, or the delivery of malicious payloads, compromising the confidentiality and integrity of data accessed through the affected site.

Affected Systems

The flaw affects the WordPress plugin DN Sitemap Control from digireturn, specifically all releases through and including 1.0.6. System administrators should review any site employing this plugin within that version range.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity reflected XSS, while the EPSS score of < 1% suggests a low probability of widespread exploitation at the present time. The feature is not yet cataloged in CISA’s KEV list. An attacker would need to craft a malicious URL or form input that the plugin mirrors into the page, and the victim would have to visit that URL or submit the input. Because it requires user interaction, the real‑world risk depends on the site’s traffic and the attacker’s ability to entice users.

Generated by OpenCVE AI on May 1, 2026 at 14:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the DN Sitemap Control plugin to the latest release that contains the XSS remediation.
  • If an upgrade cannot be applied in a timely manner, deactivate or uninstall the plugin to stop the reflected input from being processed.
  • Verify that no legacy templates or configuration files from the old plugin remain on the server and monitor the site for any unexpected script execution.

Generated by OpenCVE AI on May 1, 2026 at 14:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5684 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound DN Sitemap Control allows Reflected XSS. This issue affects DN Sitemap Control: from n/a through 1.0.6.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound DN Sitemap Control allows Reflected XSS. This issue affects DN Sitemap Control: from n/a through 1.0.6. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digireturn DN Sitemap Control dn-sitemap-control allows Reflected XSS.This issue affects DN Sitemap Control: from n/a through <= 1.0.6.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 04 Mar 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound DN Sitemap Control allows Reflected XSS. This issue affects DN Sitemap Control: from n/a through 1.0.6.
Title WordPress DN Sitemap Control plugin <= 1.0.6 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T23:51:21.346Z

Reserved: 2025-01-16T11:29:46.482Z

Link: CVE-2025-23753

cve-icon Vulnrichment

Updated: 2025-03-04T20:13:28.560Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:46.720

Modified: 2026-06-17T08:56:55.913

Link: CVE-2025-23753

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T14:45:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')