← back
CVE-2022-0952observed exploitation

Sitemap by click5 < 1.0.36 - Unauthenticated Arbitrary Options Update

65Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 13%
from disclosure to weapon462 days
Published on NVDMay 2
1st PoC+462d
VulnCheck+610d
exploitation probability
13%top 4% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog options, such as the users_can_register and default_role, allowing them to create a new admin account and take over the blog.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.