S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0952 Scanner

Detects 'Cross-Site Request Forgery (CSRF)' vulnerability in Sitemap by click5 plugin for WordPress affects v. before 1.0.36.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0952
8.8
CVSS

The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register and default_role, allowing them to create a new admin account and take over the blog.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Sitemap by click5
AFFECTED< 1.0.36SAFE ✓≥ 1.0.36
Updated Aug 22, 2026View on NVD →
Detail

The Sitemap by click5 plugin for WordPress is a tool utilized by website owners to generate sitemaps for their website. It is commonly used to aid search engine crawlers in navigating and indexing website content. With over thousands of active installations, the plugin provides an easy way to create and submit a sitemap to Google. This plugin lets its users set up a custom sitemap for specific website content, such as blog posts, products, or categories. The Sitemap by click5 plugin is an essential tool for website owners, both small and large, looking to optimize their online presence.

The CVE-2022-0952 vulnerability detected in the Sitemap by click5 plugin for WordPress is a major security risk. The plugin was lacking in basic security protocols, such as authorization and Cross-Site Request Forgery (CSRF) checks, when updating options via a REST endpoint. This vulnerability could allow an unauthenticated attacker to change arbitrary blog options, including users_can_register and default_role. These options could enable the attacker to create a new admin account and gain control over the blog. Therefore, the Sitemap by click5 plugin could be exploited for malicious purposes leading to severe consequences.

The exploitation of the CVE-2022-0952 vulnerability in the Sitemap by click5 plugin for WordPress could have disastrous results. A malicious attacker could potentially gain unauthorized access to the website and manipulate its contents. As a result, they could delete, deface, or change website content to spread misinformation or launch phishing attacks on unsuspecting users. In the hands of a skilled attacker, this vulnerability could lead to the complete takeover of a website's control panel.

At S4E, we believe that the security of digital assets is of paramount importance. Users can utilize our platform's pro features to quickly and easily learn about vulnerabilities in their digital assets. Through our security scans, users can identify software vulnerabilities, including the CVE-2022-0952 vulnerability detected in the Sitemap by click5 plugin for WordPress. Take proactive steps to safeguard your website through our platform and show vulnerability the door.

 

REFERENCES

Solution Advice

Security precautions can be taken to protect against the CVE-2022-0952 vulnerability in the Sitemap by click5 plugin for WordPress. Here are some precautions to consider:

  • Install updates: Ensure that the plugin is always updated to the latest version. Vulnerabilities are regularly patched in software updates, so installing them can help prevent security breaches.
  • Limit access to the WordPress dashboard: Reduce the number of users with access to the WordPress administration panel. Limiting access reduces the likelihood of unauthorized modifications.
  • Enable HTTPS: Utilize a Secure Sockets Layer (SSL) protocol to encrypt all data transmitted between a website user's browser and the server. This encryption provides secure data transmission, protecting against potential exploitation of this vulnerability.
  • Use two-factor authentication: Implement two-factor authentication, requiring a password and an additional factor, such as a code sent to a mobile device, when logging into the WordPress administration panel. This security measure helps to ensure only authorized access.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.