Executive brief
WP Simple HTML Sitemap is a WordPress plugin used to generate site maps for better navigation and SEO. A security vulnerability in versions 3.8 and earlier allows an attacker with high-level privileges to inject malicious scripts into the website. If a site administrator or visitor interacts with the affected page, the attacker could potentially steal session information, redirect users to malicious sites, or deface the website.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Ashish Ajani WP Simple HTML Sitemap plugin for WordPress (versions <= 3.8) due to improper neutralization of input during web page generation. The flaw allows an attacker with 'Author' or higher privileges to inject malicious scripts that execute in the context of a victim's browser. Exploitation requires a privileged user to perform a specific action, such as clicking a crafted link or visiting a specific page. This can lead to unauthorized actions being performed in the victim's session or the theft of sensitive browser-based data. The issue is resolved in version 3.9.
Affected products
- Ashish Ajani WP Simple HTML Sitemap <= 3.8
Timeline
- 2026-01-16: disclosed: Reported by Jitlada to Patchstack
- 2026-02-15: advisory: Patchstack published the vulnerability details
- 2026-04-08: advisory: CVE published to NVD
- 2026-02-15: patched: Version 3.9 released to address the vulnerability