XML Sitemap Generator for Google [google-sitemap-generator] <= 4.1.21 (unfixed)
unknown
[en] Missing Authorization vulnerability in Auctollo Google XML Sitemaps google-sitemap-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Google XML Sitemaps: from n/a through <= 4.1.21.
- Affected:
- up to 4.1.21
- Fix:
- No patched version reported
- Disclosed:
- Dec 16, 2025
CVE-2025-64632 on NVD →
Google XML Sitemaps <= 4.1.22 - Missing Authorization
medium
The Google XML Sitemaps plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.1.22. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.1.22
- Fixed in:
- 4.1.23
- Disclosed:
- Oct 31, 2025
CVE-2025-64632 on NVD →
XML Sitemap Generator for Google [google-sitemap-generator] < 4.1.3
unknown
[en] The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 4.1.3
- Fixed in:
- 4.1.3
- Disclosed:
- Jun 20, 2022
CVE-2021-25088 on NVD →
XML Sitemaps <= 4.1.1 - Authenticated (Admin+) Cross-Site Scripting
medium
The XML Sitemaps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 4.1.1 due to insufficient input sanitization and output escaping on the Debug page. This makes it possible for authenticated attackers with administrative level permissions and abo...
- CVSS:
- 5.5
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.2
- Disclosed:
- May 30, 2022
CVE-2021-25088 on NVD →
XML Sitemap Generator for Google [google-sitemap-generator] < 4.1.0
unknown
[en] Cross-site scripting vulnerability in Google XML Sitemaps Version 4.0.9 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.0
- Disclosed:
- Jan 9, 2019
CVE-2018-16204 on NVD →
XML Sitemaps <= 4.0.9 - Authenticated Cross-Site Scripting
medium
Cross-site scripting vulnerability in Google XML Sitemaps Version 4.0.9 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS:
- 5.5
- Affected:
- up to 4.0.9
- Fixed in:
- 4.1.0
- Disclosed:
- Dec 25, 2018
CVE-2018-16204 on NVD →
XML Sitemap Generator for Google [google-sitemap-generator] < 4.0.9
unknown
The plugin contains a Paypal donate button that is echoing the global variable HTTP_HOST, which can be manipulated by the visitor.
Vulnerable Code:
sitemap-ui.php L1310
echo 'http://' . $_SERVER['HTTP_HOST']...
- Affected:
- up to 4.0.9
- Fixed in:
- 4.0.9
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database