SQL Injection Vulnerability in WP Sitemap Plugin by Jenst
CVE-2025-27312

8.5HIGH

Key Information:

Vendor
Jenst
Status
WP Sitemap
Vendor
CVE Published:
24 February 2025

Summary

The WP Sitemap Plugin by Jenst is vulnerable to SQL Injection due to improper neutralization of special elements in SQL commands. This vulnerability could allow attackers to manipulate SQL queries, compromising the security of websites running vulnerable versions of the plugin. It is essential for users to remain vigilant and update to the latest version to mitigate potential security risks.

Affected Version(s)

WP Sitemap <= 1.0

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

theviper17 (Patchstack Alliance)
.