CVE-2025-26549

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Feb 13, 2025
CWE ID 352

Summary

CVE-2025-26549 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the WP Html Page Sitemap plugin. An attacker can exploit this issue to perform Stored XSS (Cross-Site Scripting) attacks on unsuspecting users. Successful exploitation allows the attacker to inject malicious scripts into web pages viewed by the victim, potentiallyleading to data theft or other malicious activities. The vulnerability exists in versions 2.2 and earlier of the plugin. Users are strongly advised to update to the latest version or consider disabling the plugin as a temporary measure to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share