CVE-2025-39413

WordPress Simple Sitemap – Create a Responsive HTML Sitemap plugin <= 3.5.14 - Broken Access Control vulnerability

Missing Authorization vulnerability in David Gwyer Simple Sitemap – Create a Responsive HTML Sitemap.This issue affects Simple Sitemap – Create a Responsive HTML Sitemap: from n/a through 3.5.14.


We have discovered 728 live websites that are affected by CVE-2025-39413.

Run a Free Instant Scan




Affected Software

Product  Simple Sitemap
Category Wordpress Plugins
Vulnerable Domains728 live websites (100% of Simple Sitemap install base)
Vulnerable Versions
  • from 0 through 3.5.14
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Apr 30, 2025
  • Updated - Apr 30, 2025

Credits

  • Ananda Dhakal (Patchstack) (finder)

Website Distribution by Country

Number of websites using CVE-2025-39413
United States249 websites



Poland89 websites
Russia59 websites
France53 websites
GB45 websites
Germany37 websites
Australia17 websites
Netherlands17 websites
Israel15 websites
Japan15 websites

Website Distribution by TLD

Number of websites using CVE-2025-39413
.com286 websites
.pl68 websites
.ru52 websites
.co.uk31 websites
.org29 websites
.fr26 websites
.de20 websites
.net16 websites
.nl14 websites
.com.au14 websites

Websites affected by CVE-2025-39413

Top websites that are affected by CVE-2025-39413. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.be Netherlands**,***
**********************.com United States**,***
************.com France**,***
*******************.org United States***,***
*********.com United States***,***
***************.**.uk GB***,***
***.*********.fr France***,***
***********.ca Canada***,***
********.com United States***,***
*************.dk Denmark***,***
See full domain list

FAQ

CVE-2025-39413 is Missing Authorization in Simple Sitemap
A total of 728 websites have been identified as vulnerable to CVE-2025-39413, based on global website indexing conducted by WebTechSurvey.
The Simple Sitemap is affected by the CVE-2025-39413 vulnerability.
Simple Sitemap versions up to and including 3.5.14 are vulnerable to CVE-2025-39413.