Executive brief
Kwayy HTML Sitemap is a WordPress plugin used to generate sitemaps for websites. A security flaw in versions 4.0 and earlier allows an attacker to trick a site administrator into performing unintended actions, such as changing plugin settings. This could lead to further attacks, including the injection of malicious scripts that could compromise the website or its visitors.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Kwayy HTML Sitemap plugin for WordPress (versions <= 4.0) due to missing nonce validation on administrative actions. An unauthenticated remote attacker can exploit this by tricking a logged-in administrator into clicking a malicious link or visiting a specially crafted webpage. Successful exploitation allows the attacker to modify plugin settings, which can be leveraged to perform Stored Cross-Site Scripting (XSS). As of the advisory date, no official patch is available.
Affected products
- Bimal Rekhadiya Kwayy HTML Sitemap <= 4.0
Timeline
- 2026-06-15: other: Vulnerability reported by researcher
- 2026-07-23: disclosed: Public disclosure of the vulnerability