๐Ÿ” CVE Alert

CVE-2026-22355

HIGH 7.1

WordPress Simple XML Sitemap plugin <= 1.3 - CSRF to Stored XSS vulnerability

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

Cross-Site Request Forgery (CSRF) vulnerability in gregmolnar Simple XML Sitemap simple-xml-sitemap allows Stored XSS.This issue affects Simple XML Sitemap: from n/a through <= 1.3.

CWE CWE-352
Vendor gregmolnar
Product simple xml sitemap
Published Jan 22, 2026
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for gregmolnar simple xml sitemap

Be the first to know when new high vulnerabilities affecting gregmolnar simple xml sitemap are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

gregmolnar / Simple XML Sitemap
0 โ‰ค 1.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/simple-xml-sitemap/vulnerability/wordpress-simple-xml-sitemap-plugin-1-3-csrf-to-stored-xss-vulnerability?_s_id=cve

Credits

Skalucy | Patchstack Bug Bounty Program