CVE-2022-4472

Simple Sitemap < 3.5.8 - Contributor+ Stored XSS

The Simple Sitemap WordPress plugin before 3.5.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.


We have discovered 636 live websites that are affected by CVE-2022-4472.

Run a Free Instant Scan




Affected Software

Product  Simple Sitemap
Category Wordpress Plugins
Vulnerable Domains636 live websites (100% of Simple Sitemap install base)
Vulnerable Versions
  • from 0 through 3.5.8
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jan 30, 2023
  • Updated - Mar 28, 2025

Credits

  • Lana Codes (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2022-4472
United States216 websites



Poland87 websites
Russia56 websites
GB41 websites
France38 websites
Germany29 websites
Australia16 websites
Israel14 websites
Netherlands13 websites
Italy12 websites

Website Distribution by TLD

Number of websites using CVE-2022-4472
.com238 websites
.pl68 websites
.ru49 websites
.co.uk31 websites
.org23 websites
.fr20 websites
.net15 websites
.de15 websites
.com.au12 websites
.nl10 websites

Websites affected by CVE-2022-4472

Top websites that are affected by CVE-2022-4472. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.be Netherlands**,***
**********************.com United States**,***
************.com France**,***
*******************.org United States***,***
*********.com United States***,***
***************.**.uk GB***,***
***.*********.fr France***,***
***********.ca Canada***,***
********.com United States***,***
*************.dk Denmark***,***
See full domain list

FAQ

CVE-2022-4472 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Simple Sitemap
A total of 636 websites have been identified as vulnerable to CVE-2022-4472, based on global website indexing conducted by WebTechSurvey.
The Simple Sitemap is affected by the CVE-2022-4472 vulnerability.
Simple Sitemap versions up to 3.5.8 are vulnerable to CVE-2022-4472.
CVE-2022-4472 is resolved in version 3.5.8 of Simple Sitemap.