Junglewise Threat Intelligence

CVE-2026-39654: Ashish Ajani WP Simple HTML Sitemap DOM-based XSS

CVE-2026-39654 · Severity: medium · CVSS 5.9 · Published 2026-04-08

Executive brief

WP Simple HTML Sitemap is a WordPress plugin used to generate site maps for better navigation and SEO. A security vulnerability in versions 3.8 and earlier allows an attacker with high-level privileges to inject malicious scripts into the website. If a site administrator or visitor interacts with the affected page, the attacker could potentially steal session information, redirect users to malicious sites, or deface the website.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Ashish Ajani WP Simple HTML Sitemap plugin for WordPress (versions <= 3.8) due to improper neutralization of input during web page generation. The flaw allows an attacker with 'Author' or higher privileges to inject malicious scripts that execute in the context of a victim's browser. Exploitation requires a privileged user to perform a specific action, such as clicking a crafted link or visiting a specific page. This can lead to unauthorized actions being performed in the victim's session or the theft of sensitive browser-based data. The issue is resolved in version 3.9.

Affected products

  • Ashish Ajani WP Simple HTML Sitemap <= 3.8

Timeline

  • 2026-01-16: disclosed: Reported by Jitlada to Patchstack
  • 2026-02-15: advisory: Patchstack published the vulnerability details
  • 2026-04-08: advisory: CVE published to NVD
  • 2026-02-15: patched: Version 3.9 released to address the vulnerability

References