Releases83
Frequency2 weeks 4 days
Last Release
Generate a sitemap for your Astro site

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
< 4.45.4 MEDIUM

The Sitemap WordPress plugin before 4.4 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

< 1.0.368.8 HIGH6.8 MEDIUM

The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register and default_role, allowing them to create a new admin account and take over the blog.