CVE-2025-26549
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-26549 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the WP Html Page Sitemap plugin. An attacker can exploit this issue to perform Stored XSS (Cross-Site Scripting) attacks on unsuspecting users. Successful exploitation allows the attacker to inject malicious scripts into web pages viewed by the victim, potentiallyleading to data theft or other malicious activities. The vulnerability exists in versions 2.2 and earlier of the plugin. Users are strongly advised to update to the latest version or consider disabling the plugin as a temporary measure to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress