CVE-2023-6492

Simple Sitemap <= 3.5.13 - Cross-Site Request Forgery via admin_notices

The Simple Sitemap – Create a Responsive HTML Sitemap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.13. This is due to missing or incorrect nonce validation in the 'admin_notices' hook found in class-settings.php. This makes it possible for unauthenticated attackers to reset the plugin options to a default state via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.


We have discovered 684 live websites that are affected by CVE-2023-6492.

Run a Free Instant Scan




Affected Software

Product  Simple Sitemap
Category Wordpress Plugins
Vulnerable Domains684 live websites (100% of Simple Sitemap install base)
Vulnerable Versions
  • from 0 through 3.5.13
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)



Details

  • Published - Jun 14, 2024
  • Updated - Aug 2, 2024

Credits

  • Rafshanzani Suhada (finder)

Website Distribution by Country

Number of websites using CVE-2023-6492
United States234 websites



Poland87 websites
Russia57 websites
France50 websites
GB44 websites
Germany33 websites
Australia16 websites
Netherlands14 websites
Israel14 websites
Italy13 websites

Website Distribution by TLD

Number of websites using CVE-2023-6492
.com265 websites
.pl68 websites
.ru50 websites
.co.uk31 websites
.org26 websites
.fr25 websites
.de17 websites
.net16 websites
.com.au13 websites
.nl11 websites

Websites affected by CVE-2023-6492

Top websites that are affected by CVE-2023-6492. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.be Netherlands**,***
**********************.com United States**,***
************.com France**,***
*******************.org United States***,***
*********.com United States***,***
***************.**.uk GB***,***
***.*********.fr France***,***
***********.ca Canada***,***
********.com United States***,***
*************.dk Denmark***,***
See full domain list

FAQ

A total of 684 websites have been identified as vulnerable to CVE-2023-6492, based on global website indexing conducted by WebTechSurvey.
The Simple Sitemap is affected by the CVE-2023-6492 vulnerability.
Simple Sitemap versions up to and including 3.5.13 are vulnerable to CVE-2023-6492.