The Simple Sitemap WordPress plugin before 3.5.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
We have discovered 636 live websites that are affected by CVE-2022-4472.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 636 live websites (100% of Simple Sitemap install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 0 versions ( less than 0.1% of all versions) |
| 216 websites | |
| 87 websites | |
| 56 websites | |
| 41 websites | |
| 38 websites | |
| 29 websites | |
| 16 websites | |
| 14 websites | |
| 13 websites | |
| 12 websites |
| .com | 238 websites |
| .pl | 68 websites |
| .ru | 49 websites |
| .co.uk | 31 websites |
| .org | 23 websites |
| .fr | 20 websites |
| .net | 15 websites |
| .de | 15 websites |
| .com.au | 12 websites |
| .nl | 10 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **************.be | **,*** | ||
| **********************.com | **,*** | ||
| ************.com | **,*** | ||
| *******************.org | ***,*** | ||
| *********.com | ***,*** | ||
| ***************.**.uk | ***,*** | ||
| ***.*********.fr | ***,*** | ||
| ***********.ca | ***,*** | ||
| ********.com | ***,*** | ||
| *************.dk | ***,*** |
FAQ