Vulnerability Description
The XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an arbitrary value, thus causing XSS via error message or RCE if allow_url_include is turned on.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xmlsitemapgenerator | Xml Sitemap Generator | < 2.0.4 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/4b339390-d71a-44e0-8682-51a12bd2bfe6ExploitThird Party Advisory
- https://wpscan.com/vulnerability/4b339390-d71a-44e0-8682-51a12bd2bfe6ExploitThird Party Advisory
FAQ
What is CVE-2022-0346?
CVE-2022-0346 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an arbitrary value, thus causing XSS via error message or RCE if allow_url_include ...
How severe is CVE-2022-0346?
CVE-2022-0346 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-0346?
Check the references section above for vendor advisories and patch information. Affected products include: Xmlsitemapgenerator Xml Sitemap Generator.