Impact
Improper neutralization of input during web page generation allows attackers to embed malicious scripts in responses generated by the Digihood HTML Sitemap plugin. The reflected XSS flaw permits the injection of JavaScript via unsanitized query parameters or form inputs, enabling attackers to execute code in the context of a victim’s browser. Successful exploitation could lead to session hijacking, cookie theft, defacement, or the delivery of further malware.
Affected Systems
Digihood HTML Sitemap (WordPress plugin) versions 3.1.1 and earlier are impacted. This includes all WordPress sites deploying the plugin up to and including version 3.1.1 with no post‑update remediation.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact vulnerability, but the EPSS score of less than 1% shows a very low probability of exploitation at present. The flaw is not currently listed in the CISA KEV catalog, and no public exploits have been disclosed. Attackers could craft a malicious URL that includes the injection payload, which is then reflected in the sitemap page rendered by the plugin. The lack of input validation (CWE‑79) is the root cause.
OpenCVE Enrichment
EUVD