Impact
Based on the description, the Kwayy HTML Sitemap plugin for WordPress contains an unauthenticated Cross‑Site Request Forgery flaw that permits an attacker to inject arbitrary HTML into the plugin’s configuration page. Because the injected content is stored and subsequently rendered on sitemap pages, the vulnerability functions as a stored Cross‑Site Scripting vector, allowing malicious scripts to execute in the browsers of site visitors and potentially leading to session hijacking, defacement or malware delivery.
Affected Systems
All WordPress installations that use the Kwayy HTML Sitemap plugin version 4.0 or earlier are affected. Site administrators using the plugin from vendor Bimal Rekhadiya should verify the plugin version and compare it against the list of susceptible releases.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1% suggests that exploitation is currently unlikely but still possible. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker sending a crafted link or form that triggers the plugin’s configuration endpoint via a user’s browser, storing malicious payloads that will be served to all visitors who access the affected sitemap page. No additional privileges or service exposure are required beyond a normal visitor role.
OpenCVE Enrichment